Opened 3 years ago

Last modified 3 months ago

#21657 new task

Test to make sure we isolate or disable all speculative connects — at Version 2

Reported by: arthuredelstein Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-linkability, ff52-esr, TorBrowserTeam201805
Cc: luke.crouch@… Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description (last modified by arthuredelstein)

There are a variety of "resource hint" features in Tor Browser that we want to make sure are isolated by first-party or disabled. These include

  link rel=preconnect
  link rel=prefetch
  link rel=prerender

and possibly more.
We should test this for the ESR45 and ESR52 versions of Tor Browser, because isolation will have different mechanisms.

See https://w3c.github.io/resource-hints/

We should also look into "SpeculativeConnect" code in Firefox to make sure there aren't any other cases of non-first-party isolated connections.

Child Tickets

Change History (2)

comment:1 Changed 3 years ago by arthuredelstein

Description: modified (diff)

comment:2 Changed 3 years ago by arthuredelstein

Description: modified (diff)
Note: See TracTickets for help on using tickets.