[tbb-bugs] #28371 [Applications/Tor Browser]: verify that speculative connect on mousedown does not violate FPI
Tor Bug Tracker & Wiki
blackhole at torproject.org
Wed Nov 7 20:19:12 UTC 2018
#28371: verify that speculative connect on mousedown does not violate FPI
-------------------------------------+-------------------------------------
Reporter: mcs | Owner: tbb-team
Type: defect | Status: new
Priority: Medium | Milestone:
Component: Applications/Tor | Version:
Browser | Keywords: tbb-
Severity: Normal | linkability,ff60-esr
Actual Points: | Parent ID:
Points: | Reviewer:
Sponsor: |
-------------------------------------+-------------------------------------
In Firefox 55, Firefox added code to speculatively connect when a user
mousedowns over a link. We should verify that the early connection does
not bypass first party isolation (if it does, it seems like we would have
noticed by now... but we should double-check).
See https://bugzilla.mozilla.org/show_bug.cgi?id=1348278
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/28371>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tbb-bugs
mailing list