[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-bugs] Re: #628 [Tor-Torbutton]: Language cloaking doesn't hide character set



#628: Language cloaking doesn't hide character set
-----------------------+----------------------------------------------------
 Reporter:  sjmurdoch  |         Type:  defect       
   Status:  new        |     Priority:  major        
Milestone:             |    Component:  Tor-Torbutton
  Version:  1.1        |   Resolution:  None         
 Keywords:             |  
-----------------------+----------------------------------------------------
Changes (by mikeperry):

  * priority:  minor => major


Old description:

> Tor Button spoofs US English in the "Accept-Language" HTTP, if
> configured. This is helpful in increasing
> the size of the anonymity set. However, the "Accept-Charset" header is
> not spoofed, which leaks language
> information. For example, the Simplified Chinese version of the Tor
> Browser Bundle includes gb2312 in the
> accepted character sets, indicating Chinese. Is there any reason not to
> spoof this header too?
>
> [Automatically added by flyspray2trac: Operating System: All]

New description:

 Tor Button spoofs US English in the "Accept-Language" HTTP, if configured.
 This is helpful in increasing
 the size of the anonymity set. However, the "Accept-Charset" header is not
 spoofed, which leaks language
 information. For example, the Simplified Chinese version of the Tor
 Browser Bundle includes gb2312 in the
 accepted character sets, indicating Chinese. Is there any reason not to
 spoof this header too?

 [Automatically added by flyspray2trac: Operating System: All]

--

Comment:

 See also bug #1089.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/628#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online