[tbb-bugs] #20019 [Applications/Tor Browser]: Proposal for TOR Browser extension

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Oct 9 18:03:05 UTC 2016


#20019: Proposal for TOR Browser extension
--------------------------------------+-----------------------------------
 Reporter:  SECUSO_Kristoffer         |          Owner:  tbb-team
     Type:  enhancement               |         Status:  needs_information
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+-----------------------------------

Comment (by SECUSO_Kris):

 Replying to [comment:4 teor]:

 > The random, persistent choice of icon is vulnerable to server probing
 via HTML Canvas, and perhaps other mechanisms.
 >
 > If it's made persistent on disk, it's also vulnerable to file
 fingerprinting, allowing forensic analysis to discover the choice of icon
 even if Tor is restarted or "new identity" is chosen.

 Thanks for answer. What do you think of the following idea: We keep the
 highlighted password and form fields but we remove the yellow/green icons.
 The warning dialogs should be fine as well because they are the same for
 every user.

 (Sorry for replying with a new account but I wasn't able to reset my
 password)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20019#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list