[tor-bugs] #12468 [Tor bundles/installation]: TBB unconditionally logs all Firefox output to disk

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Jun 26 10:17:55 UTC 2014


#12468: TBB unconditionally logs all Firefox output to disk
--------------------------------------+-----------------------
 Reporter:  rransom                   |          Owner:  erinn
     Type:  defect                    |         Status:  new
 Priority:  blocker                   |      Milestone:
Component:  Tor bundles/installation  |        Version:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
--------------------------------------+-----------------------
 Previously, Tor Browser Bundle's startup script would check whether its
 stdout and stderr are pointed at a terminal, and
 [https://gitweb.torproject.org/builders/tor-browser-
 bundle.git/blob/c2bd8a5f070e771623aebfb66e95e9e954e5522d:/RelativeLink/RelativeLink.sh#l131
 close them otherwise] (unless the user is explicitly running TBB in debug
 mode).  This allowed power users to easily view TBB's error messages in a
 terminal, while ensuring that novice users who start TBB from a GUI file
 manager would not accidentally leave evidence that they had used TBB in
 `~/.xsession-errors`.

 Now, the startup script '''unconditionally'''
 [https://gitweb.torproject.org/builders/tor-browser-
 bundle.git/commitdiff/c2bd8a5f070e771623aebfb66e95e9e954e5522d redirects
 Firefox's output into a disk file], and according to
 [ticket:11751#comment:6], that disk file will contain sensitive
 information (“it often includes full URIs logged from HTTPSEverywhere”).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12468>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list