Opened 2 years ago

Closed 2 years ago

Last modified 22 months ago

#26067 closed defect (duplicate)

Downloading of images through different circuits than the ones used to view them causes data corruption and incorrect files

Reported by: fufufu Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Major Keywords:
Cc: dmr Actual Points:
Parent ID: #22343 Points:
Reviewer: Sponsor:


  1. You view an image in Tor Browser, right-click on it, and hit "Save Image As" to download it.
  1. The download appears to complete normally, Tor Browser shows no error or that the download has failed, and the image is seemingly on your computer.
  1. However, because Tor Browser picks a new circuit every time you choose to save an image, one that is different than the one used to actually deliver it to you as you see it in your browser, and because you got unlucky this time with the resultant IP address selected, instead of saving your image, you end up saving Cloudflare's "Attention Required" page with the name of your image, or one of those "Your IP address has been blacklisted." pages, or some other file that is not a valid image. When you go to view the "image", it is corrupt, invalid, and unviewable from the perspective of most image viewers as it has no valid image header. If the image somehow disappeared from the Internet before you noticed this, then you will never have it.
  1. Furthermore, there is no way to manually refresh the circuit selected to save the image (as opposed to the one used to view it), so if you do recognize this bug, and you have a bad image saving circuit currently open, then you have to wait 10 minutes to hopefully get a better one.

Tor Browser should use the same circuit to download an image as the one that it uses to actually display it to you in the browser to prevent these errors.

(This also applies to viewing the source code of pages.)

Child Tickets

Change History (6)

comment:1 Changed 2 years ago by fufufu

Severity: NormalMajor
Version: Tor: unspecified

comment:2 Changed 2 years ago by cypherpunks

Keywords: images saving downloading removed

I bet 0.002 Satoshian Moneros that this is a duplicate, go figure!

comment:3 Changed 2 years ago by cypherpunks

comment:4 Changed 2 years ago by fufufu

Oh, sorry then

comment:5 Changed 2 years ago by gk

Resolution: duplicate
Status: newclosed

comment:6 in reply to:  5 Changed 22 months ago by dmr

Cc: dmr added
Parent ID: #22343

Replying to gk:

[close as duplicate]

Assigning a parent relationship - hope that helps keep these tracked together.
(Please lmk if that is against the tbb workflow!)

Note: See TracTickets for help on using tickets.