[tor-talk] Security issue

Gerardus Hendricks konfkukor at riseup.net
Tue Jan 21 00:25:13 UTC 2014


On 1/20/14 11:53 PM, tortestprivacy tortestprivacy wrote:
> With Tor Browser Bundle default settings any web-site can access to
> local resources by JavaScript and XMLHttpRequest.

Could you please explain why the same-origin policy of Firefox doesn't 
prevent this?


More information about the tor-talk mailing list