Opened 8 years ago

Closed 7 years ago

#3737 closed defect (user disappeared)

kissmetrics exploits

Reported by: cypherpunks Owned by: mikeperry
Priority: Medium Milestone:
Component: TorBrowserButton Version:
Severity: Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Can torbutton in current or future iteration protect against the kissmetrics browser exploits?

http://ashkansoltani.org/docs/respawn_redux.html

Child Tickets

Change History (2)

comment:1 Changed 8 years ago by mikeperry

Status: newneeds_information

Great, another hit and run cypherpunks ticket with insufficient detail...

AFAIK, we do prevent this type of cookie respawn: DOM storage and flash are disabled, and if you enable flash, BetterPrivacy should kick in on TBB and clear your flash cookies for you...

Can you explain what you believe to be the shortcoming here?

Also note that I have just finished an implementation of #523 to clear cache, http auth, ssl state, etc etc in TBB..

comment:2 Changed 7 years ago by mikeperry

Resolution: user disappeared
Status: needs_informationclosed
Note: See TracTickets for help on using tickets.