Opened 4 years ago

Last modified 16 months ago

#8916 reopened defect

Windows Prefetch records the Tor Browser Bundle

Reported by: runa Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-disk-leak
Cc: runa Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

A forensic analysis of the Tor Browser Bundle (version 2.3.25-6, 64-bit) on Windows 7 showed that the Windows Prefetcher keeps records of the different Tor Browser Bundle applications:

  • C:\Windows\Prefetch\START TOR BROWSER.EXE-F5557FAC.pf
  • C:\Windows\Prefetch\TBB-FIREFOX.EXE-350502C5.pf
  • C:\Windows\Prefetch\TOR-BROWSER-2.3.25-6\_EN-US.EX-1354A499.pf
  • C:\Windows\Prefetch\TOR.EXE-D7159D93.pf
  • C:\Windows\Prefetch\VIDALIA.EXE-5167E0BC.pf

The following cache files are most likely similar to prefetch files and might contain traces of the Tor Browser Bundle:

  • C:\Users\runa\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Users\runa\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000006.db
  • C:\Windows\AppCompat\Programs\RecentFileCache.bcf

Child Tickets

Change History (6)

comment:1 Changed 4 years ago by runa

  • Keywords tbb-disk-leak added

comment:2 Changed 4 years ago by runa

It is possible to disable Prefetch, but I am not sure if it's something we want to recommend to our users.

comment:3 Changed 3 years ago by erinn

  • Keywords needs-triage added

comment:4 Changed 3 years ago by erinn

  • Component changed from Tor bundles/installation to Tor Browser
  • Owner changed from erinn to tbb-team

comment:5 Changed 16 months ago by bugzilla

  • Keywords tbb-disk-traces added; tbb-disk-leak needs-triage removed
  • Resolution set to not a bug
  • Severity set to Normal
  • Status changed from new to closed

You'd never be able to remove OS "logging" under non-admin credentials. It is not a leak, but traces.

comment:6 Changed 16 months ago by gk

  • Keywords tbb-disk-leak added; tbb-disk-traces removed
  • Resolution not a bug deleted
  • Status changed from closed to reopened

Please, don't invent new keywords out of the box and don't close tickets even if there is no obvious workaround or fix imaginable at the moment. Thanks.

Note: See TracTickets for help on using tickets.