[tahoe-lafs-trac-stream] [tahoe-lafs] #1942: google chart in wui leaks information

tahoe-lafs trac at tahoe-lafs.org
Wed Apr 10 22:12:14 UTC 2013


#1942: google chart in wui leaks information
-------------------------+-------------------------------------------------
     Reporter:  leif     |      Owner:  daira
         Type:  defect   |     Status:  assigned
     Priority:  normal   |  Milestone:  undecided
    Component:  unknown  |    Version:  1.9.2
   Resolution:           |   Keywords:  anonymity privacy integrity
Launchpad Bug:           |  confidentiality security capleak
-------------------------+-------------------------------------------------
Changes (by daira):

 * keywords:  anonymity privacy => anonymity privacy integrity
     confidentiality security capleak
 * owner:  davidsarah => daira
 * status:  new => assigned


Comment:

 +1. It also potentially gives Google access to other pages (that are
 related in the browsing history) of the gateway's local origin.

 We should put a note in [source:git/docs/known_issues.rst] for 1.10, and
 switch to using {{{d3.js}}} for 1.11.

 There don't appear to be any other uses of Google Charts other than the
 mutable servermap update status page.

-- 
Ticket URL: <https://tahoe-lafs.org/trac/tahoe-lafs/ticket/1942#comment:2>
tahoe-lafs <https://tahoe-lafs.org>
secure decentralized storage


More information about the tahoe-lafs-trac-stream mailing list