[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #3600 [TorBrowserButton]: We should get user confirmation for automated redirect cycles (was: We should get user confirmation for redirects)
#3600: We should get user confirmation for automated redirect cycles
------------------------------+---------------------------------------------
Reporter: mikeperry | Owner: mikeperry
Type: defect | Status: new
Priority: major | Milestone: TorBrowserBundle 2.3.x-stable
Component: TorBrowserButton | Version:
Keywords: | Parent:
Points: | Actualpoints:
------------------------------+---------------------------------------------
Comment(by mikeperry):
pde pointed out that without exceptions, prompting for all redirects is
going to cause warning fatigue, especially now that both google and
twitter use them by default for click tracking.
So instead, let's try to address the linkability issue. We should prompt
for automated redirect cycles that bounce off an intermediate site without
prompting the user before returning to a previous site in the redirect
chain. Such automated cycles would be evidence of parternerships
attempting to elevate ad servers to first-party status.
We can track these cycles with a navigation observer, but it will be a fun
challenge to differentiate automated redirects from those that stop for
user input from XPCOM. We may need to alter some APIs. :/
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3600#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs