Opened 5 years ago

Last modified 3 years ago

#9456 new enhancement

Reset file attribute information after usage

Reported by: naif Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-disk-leak
Cc: mikeperry, arthuredelstein Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

TorBrowser bundle leak "local" information on when it was last used .

This is because the local filesystem keep MAC (modified, access, creation) time.

It means that from a forensic analyst perspective it will be always possible to identify which is the last time the TorBrowser has been started (and probably when it has been closed) by carefully looking at the "atime" attribute of the filesystem in the directory where TBB is stored.

To fix this issue the TBB, on start and on close, should reset the "atime attribute" of all the files and directory where it is stored.

This can be done on all major filesystem with proper programming API (FAT32, NTFS, HFS, Ext4, etc) .

Child Tickets

Change History (7)

comment:1 Changed 5 years ago by naif

Someone from irc suggested to Timestomp for windows as a tool to reset MAC timing http://www.forensicswiki.org/wiki/Timestomp

comment:2 Changed 5 years ago by runa

Cc: mikeperry added
Keywords: tbb-disk-leak added

comment:3 Changed 4 years ago by erinn

Keywords: needs-triage added

comment:4 Changed 4 years ago by erinn

Component: Tor bundles/installationTor Browser
Owner: changed from erinn to tbb-team

comment:5 Changed 4 years ago by arthuredelstein

Cc: arthuredelstein added

comment:6 Changed 3 years ago by bugzilla

Keywords: tbb-disk-traces added; tbb-disk-leak needs-triage removed
Severity: Normal
Summary: TorBrowser bundle leak "local" information on when it was last usedReset file attribute information after usage
Type: defectenhancement

This is because the local filesystem keep MAC (modified, access, creation) time.

This is because the OS updates it. But it is a good idea to make portable TBB look like "new". And not only TBB...

comment:7 Changed 3 years ago by gk

Keywords: tbb-disk-leak added; tbb-disk-traces removed
Note: See TracTickets for help on using tickets.