Skip to content
GitLab
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • Tor Browser Tor Browser
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 836
    • Issues 836
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 6
    • Merge requests 6
  • Deployments
    • Deployments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • The Tor Project
  • Applications
  • Tor BrowserTor Browser
  • Issues
  • #16673
Closed
Open
Issue created Jul 27, 2015 by Mike Perry@mikeperryDeveloper

Isolate/Disable HTTP Alternative-Services

HTTP Alternative Services header (https://tools.ietf.org/html/draft-ietf-httpbis-alt-svc-06) allows websites to tell clients to cache destination and protocol settings for certain websites.

While this header enables things like opportunistic encryption, http2 discovery, etc, unfortunately it is both a supercookie vector and a third party tracking vector. Luckily for us, it was disabled for Firefox 38 because the initial implementation also enabled URL bar spoofing vulnerabilities.

However, for Firefox 45, we will either need to isolate it, or ensure it remains disabled.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking