[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #16926 [Tor Browser]: Multiple OS: Tor Browser leaks domains to system DNS management.



#16926: Multiple OS: Tor Browser leaks domains to system DNS management.
-------------------------------+------------------------------
     Reporter:  DrMikeTwiddle  |      Owner:  tbb-team
         Type:  defect         |     Status:  new
     Priority:  critical       |  Milestone:
    Component:  Tor Browser    |    Version:  Tor: unspecified
   Resolution:                 |   Keywords:
Actual Points:                 |  Parent ID:
       Points:                 |
-------------------------------+------------------------------

Comment (by DrMikeTwiddle):

 @cypherpunks

 I lack the knowledge to assess the code, but very much believe you are
 correct in that it would seem unlikely . As an end user (and supporter of
 Tor) Iâve heavily tested TB (and also just regular Firefox+ VPN including
 with a bunch of plug ins in reg FF) and no leak has ever come up in formal
 testing, in Wireshark, tcpdump, and so on. Ever.

 Thatâs why Iâm so surprised. Of course it is difficult for me to assess
 how broken my own system is. Itâs not impossible Iâve installed something
 at some point in time to the system itself that could be a factor. I canât
 rule that out.  But it would have to be something that explicitly grabs a
 URL  out of the address bar and does a DNS look up on it but *extremely
 infrequently*.

 And because this is so infrequent - itâs happened only once and I canât
 yet repeat it, it does make me feel it is not yet possible to rule out
 some leak, however odd or rare and difficult to trigger from TB or its
 pluggable transport packages (like obsf3/4 which I tend to use due to ISP
 problems here)

 I see a new bug has been filed by teor about a potential leak from testing
 Tor (using chutney I think) OS X:

 https://trac.torproject.org/projects/tor/ticket/16971

 And then there was also the original report about DNS leaks on Linux.

 My own testing is continuing.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16926#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs