[tor-bugs] #15502 [Tor Browser]: Blob URIs considered harmful

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 30 16:01:01 UTC 2015


#15502: Blob URIs considered harmful
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:  tbb-team
  mikeperry              |     Status:  new
         Type:  defect   |  Milestone:
     Priority:  major    |    Version:
    Component:  Tor      |   Keywords:  tbb-linkability, tbb-newnym,
  Browser                |  TorBrowserTeam201503, tbb-4.5-alpha
   Resolution:           |  Parent ID:
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------
Changes (by mcs):

 * cc: brade, mcs (added)


Comment:

 This is definitely a scary feature. Did Mozilla really intend for blob:
 URIs created in document A to be accessible from document N? I wonder what
 the use case is? I agree with gk that disabling support for
 createObjectURL() is a good idea (I cannot imagine that it is widely
 used).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/15502#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list