[tor-talk] Should DOM storage really be enabled by default in TorBrowser?

Georg Koppen gk at torproject.org
Fri Jun 20 14:49:17 UTC 2014


Aymeric Vitte:
> 
> So the logic is: we accept non third party cookies, therefore we accept
> localStorage and we suppose localStorage is disabled for third parties.

[snip]

> And what's the point of allowing localStorage if you allow non third
> party cookies?

That is covered in

https://www.torproject.org/projects/torbrowser/design/#philosophy

See the whole design document for getting our idea(s). Why we are not
allowing 3rd party cookies yet is explained in 4.5.1. DOM Storage is the
subject of section 4.5.4.

The commit I've been talking about is
https://gitweb.torproject.org/tor-browser.git/commit/5392d2ed679eaaa078f5c667573ef0698ec65345

Georg


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: OpenPGP digital signature
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20140620/53ec7cfb/attachment.sig>


More information about the tor-talk mailing list