[tbb-bugs] #17367 [Applications/Tor Browser]: Swap files can contain evidence of browsing history
Tor Bug Tracker & Wiki
blackhole at torproject.org
Mon Oct 24 19:10:52 UTC 2016
#17367: Swap files can contain evidence of browsing history
--------------------------------------+--------------------------
Reporter: arthuredelstein | Owner: tbb-team
Type: defect | Status: new
Priority: Medium | Milestone:
Component: Applications/Tor Browser | Version:
Severity: Major | Resolution:
Keywords: tbb-disk-leak | Actual Points:
Parent ID: #17208 | Points:
Reviewer: | Sponsor:
--------------------------------------+--------------------------
Description changed by arthuredelstein:
Old description:
> Two forensic reports describe extracting Tor Browser browsing history
> from a Windows pagefile.sys and hiberfil.sys:
>
> See
> http://computerforensicsblog.champlain.edu/wp-content/uploads/2014/05
> /Uncovering-the-Covered-Tracks-Finding-What%E2%80%99s-Left-Behind-Saliba-
> Landry-5-19-2014.pdf#33
> and
> https://web.archive.org/web/20160403075329/http://dfrws.org/2015eu/proceedings
> /DFRWS-EU-2015-short-presentation-1.pdf#16
>
> Is there any way we can programmatically clean up the pagefile on New
> Identity and/or browser exit? What about OS X and Linux?
New description:
Two forensic reports describe extracting Tor Browser browsing history from
a Windows pagefile.sys and hiberfil.sys:
See
http://computerforensicsblog.champlain.edu/wp-content/uploads/2014/06/One-
User-Multiple-Devices-Cross-Platform-Recovery-and-Analysis...-Saliba-
Landry-5-20-2014.pdf#33
and
https://web.archive.org/web/20160403075329/http://dfrws.org/2015eu/proceedings
/DFRWS-EU-2015-short-presentation-1.pdf#16
Is there any way we can programmatically clean up the pagefile on New
Identity and/or browser exit? What about OS X and Linux?
--
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17367#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tbb-bugs
mailing list