[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-bugs] Re: [Tor Bug Tracker & Wiki] #524: Better refspoofing



#524: Better refspoofing
-----------------------+----------------------------------------------------
 Reporter:  mikeperry  |         Type:  enhancement  
   Status:  new        |     Priority:  major        
Milestone:  1.4        |    Component:  Tor-Torbutton
  Version:  1.1        |   Resolution:  None         
 Keywords:             |  
-----------------------+----------------------------------------------------
Changes (by mikeperry):

  * priority:  minor => major


Old description:

> Not sure if we want to do this or not, but it may be a good idea to do
> better referrer spoofing instead
> of just blocking referrer all together (which is disabled by default
> because some sites refuse to serve
> images/media with no referer). The RefSpoof extension has a mode to set
> the referrer to the document root
> of a site. This code may be useful to assimilate, or we can just
> encourage people to install that extension
> if the default behavior doesn't work for them. It is possible this "set
> to root" site will still break
> sites that expect image refs to come from other paths on the site only...
> In this case, refspoof's
> complete functionality may be a good idea.
>
> [Automatically added by flyspray2trac: Operating System: All]

New description:

 Not sure if we want to do this or not, but it may be a good idea to do
 better referrer spoofing instead
 of just blocking referrer all together (which is disabled by default
 because some sites refuse to serve
 images/media with no referer). The RefSpoof extension has a mode to set
 the referrer to the document root
 of a site. This code may be useful to assimilate, or we can just encourage
 people to install that extension
 if the default behavior doesn't work for them. It is possible this "set to
 root" site will still break
 sites that expect image refs to come from other paths on the site only...
 In this case, refspoof's
 complete functionality may be a good idea.

 [Automatically added by flyspray2trac: Operating System: All]

--

Comment:

 This is implemented in 'master', however, we probably want the mechanism
 from JonDoFox, at least as an additional option.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/524#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online