[tor-bugs] #12468 [Tor bundles/installation]: TBB unconditionally logs all Firefox output to disk
Tor Bug Tracker & Wiki
blackhole at torproject.org
Thu Jun 26 10:17:55 UTC 2014
#12468: TBB unconditionally logs all Firefox output to disk
--------------------------------------+-----------------------
Reporter: rransom | Owner: erinn
Type: defect | Status: new
Priority: blocker | Milestone:
Component: Tor bundles/installation | Version:
Keywords: | Actual Points:
Parent ID: | Points:
--------------------------------------+-----------------------
Previously, Tor Browser Bundle's startup script would check whether its
stdout and stderr are pointed at a terminal, and
[https://gitweb.torproject.org/builders/tor-browser-
bundle.git/blob/c2bd8a5f070e771623aebfb66e95e9e954e5522d:/RelativeLink/RelativeLink.sh#l131
close them otherwise] (unless the user is explicitly running TBB in debug
mode). This allowed power users to easily view TBB's error messages in a
terminal, while ensuring that novice users who start TBB from a GUI file
manager would not accidentally leave evidence that they had used TBB in
`~/.xsession-errors`.
Now, the startup script '''unconditionally'''
[https://gitweb.torproject.org/builders/tor-browser-
bundle.git/commitdiff/c2bd8a5f070e771623aebfb66e95e9e954e5522d redirects
Firefox's output into a disk file], and according to
[ticket:11751#comment:6], that disk file will contain sensitive
information (“it often includes full URIs logged from HTTPSEverywhere”).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12468>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list