[tor-bugs] #9623 [TorBrowserButton]: Referers being sent from hidden service websites
Tor Bug Tracker & Wiki
blackhole at torproject.org
Thu Aug 29 17:57:49 UTC 2013
#9623: Referers being sent from hidden service websites
----------------------------------+-----------------------
Reporter: cypherpunks | Owner: mikeperry
Type: defect | Status: new
Priority: major | Milestone:
Component: TorBrowserButton | Version:
Resolution: | Keywords:
Actual Points: | Parent ID:
Points: |
----------------------------------+-----------------------
Comment (by cypherpunks):
This is not only an issue about users being tracked.
It's also bad for owners of hidden services as the addresses are getting
discovered. Maybe the user was on a private website which nobody should
learn, or at least on a private webpage on a public website.
Or maybe the referer could include login credentials, or other dangerous
information.
The current behavior doesn't really fit well with the "hidden service"
idea.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9623#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list