Torbutton 1.1.5 has been released at http://torbutton.torproject.org/dev/ The changes are small, but significant: * bugfix: Reset shutdown option if user wants to manually manage cookies * misc: Add code to detect date hooking failures to zero in on Bug #460 * new: Pref to disable "DOM Storage" during Tor usage Bug #460 is a potentially nasty issue where in some cases the Date/timezone hooks aren't properly applied. The 1.1.5 code should pop up an alert now when this is the case. The alert will say either "False [win/doc] hooking. Please report bug+website!" or "Error, double js-hook". Please report either of these ocurrances plus the website plus what else you may have been doing either here or in the bug: http://bugs.noreply.org/flyspray/index.php?do=details&id=460 In the meantime, you should be safe from timezone disclosure so long as those alerts are not present, but please be vigilant. There also is an uncomfirmed bug that in some cases cookies may not be cleared during Tor toggle (and probably only when you are using certain options also). Please keep an eye out for this one. http://bugs.noreply.org/flyspray/index.php?do=details&id=457 P.S. Thanks go to Steve Topletz of Xerobank for the DOM Storage tip. -- Mike Perry Mad Computer Scientist fscked.org evil labs
Attachment:
pgpeFGFpal4Je.pgp
Description: PGP signature