[tor-bugs] #32002 [Applications/Tor Browser]: Double-check Storage Access API for disk leaks and 3rd party cookie blocking adherence
Tor Bug Tracker & Wiki
blackhole at torproject.org
Tue Oct 8 13:48:03 UTC 2019
#32002: Double-check Storage Access API for disk leaks and 3rd party cookie
blocking adherence
-------------------------------------+-------------------------------------
Reporter: gk | Owner: tbb-team
Type: task | Status: new
Priority: Medium | Milestone:
Component: Applications/Tor | Version:
Browser | Keywords: tbb-disk-leak,
Severity: Normal | TorBrowserTeam201910
Actual Points: | Parent ID:
Points: 0.2 | Reviewer:
Sponsor: |
-------------------------------------+-------------------------------------
The [https://developer.mozilla.org/en-US/docs/Web/API/Storage_Access_API
Storage Access API] is a means to prevent trackers across origins yet to
not break authentication flows and other benign 3rd party identifier
usage.
We should make sure it's not using the disk in our default Tor Browser
mode.
Moreover, we disable third-party cookies outright, mainly because we have
not looked at the first-party isolation yet (#21905), and we should make
sure this is not bypassed in non-private-browsing-mode contexts.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/32002>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list