Opened 4 years ago

Last modified 19 months ago

#8916 reopened defect

Windows Prefetch records the Tor Browser Bundle

Reported by: runa Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-disk-leak
Cc: runa Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

A forensic analysis of the Tor Browser Bundle (version 2.3.25-6, 64-bit) on Windows 7 showed that the Windows Prefetcher keeps records of the different Tor Browser Bundle applications:

  • C:\Windows\Prefetch\START TOR BROWSER.EXE-F5557FAC.pf
  • C:\Windows\Prefetch\TBB-FIREFOX.EXE-350502C5.pf
  • C:\Windows\Prefetch\TOR-BROWSER-2.3.25-6\_EN-US.EX-1354A499.pf
  • C:\Windows\Prefetch\TOR.EXE-D7159D93.pf
  • C:\Windows\Prefetch\VIDALIA.EXE-5167E0BC.pf

The following cache files are most likely similar to prefetch files and might contain traces of the Tor Browser Bundle:

  • C:\Users\runa\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Users\runa\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000006.db
  • C:\Windows\AppCompat\Programs\RecentFileCache.bcf

Child Tickets

Change History (6)

comment:1 Changed 4 years ago by runa

Keywords: tbb-disk-leak added

comment:2 Changed 4 years ago by runa

It is possible to disable Prefetch, but I am not sure if it's something we want to recommend to our users.

comment:3 Changed 3 years ago by erinn

Keywords: needs-triage added

comment:4 Changed 3 years ago by erinn

Component: Tor bundles/installationTor Browser
Owner: changed from erinn to tbb-team

comment:5 Changed 19 months ago by bugzilla

Keywords: tbb-disk-traces added; tbb-disk-leak needs-triage removed
Resolution: not a bug
Severity: Normal
Status: newclosed

You'd never be able to remove OS "logging" under non-admin credentials. It is not a leak, but traces.

comment:6 Changed 19 months ago by gk

Keywords: tbb-disk-leak added; tbb-disk-traces removed
Resolution: not a bug
Status: closedreopened

Please, don't invent new keywords out of the box and don't close tickets even if there is no obvious workaround or fix imaginable at the moment. Thanks.

Note: See TracTickets for help on using tickets.