temporary-containers icon indicating copy to clipboard operation
temporary-containers copied to clipboard

ETag cache tracking

Open stoically opened this issue 5 years ago • 7 comments

As reported on reddit, containers are susceptible to ETag cache tracking, even though they shouldn't. Easily reproducible here. Not sure if an Bugzilla ticket already exists - might be worth filing one if not.

To mitigate right now using an Add-on, @claustromaniac's ETag Stoppa works well for that.

stoically avatar Apr 16 '20 08:04 stoically

Are you sure? I do not have the same results as you. I might use something else to mitigate, but I am 99% sure that I rely just on TC for that... before TC I was using ETag Stoppa.

Will double check on a plain vanilla profile with TC only and report back today,

Cheers

crssi avatar Apr 16 '20 09:04 crssi

Done testing. You are right, but AFAIK this was not the case in the past. I am sure I had done same tests before ditching ETag Stoppa, which was in this case duplicate.

Thank you for warning, getting ETag Stoppa back into profile right now. 😄

Cheer

crssi avatar Apr 16 '20 10:04 crssi

Yeah, it's weird that containers don't cover that, must be a bug. I guess I could add the ETag Stoppa functionality as advanced preference into TC as well :thinking:

stoically avatar Apr 16 '20 14:04 stoically

ClearURLs filters ETag headers by default as well.

stoically avatar May 06 '20 06:05 stoically

Should be fixed by Firefox 85+

stoically avatar Feb 05 '21 12:02 stoically

Hmm... FF ver 85. If I open https://lucb1e.com/rp/cookielesscookies/ in one container and set some value. Then I open the same link in another container, reload twice and I get the value entered in the first container.

But using ETag Stoppa extension everything is OK.

crssi avatar Feb 05 '21 12:02 crssi

Hm, true. So they missed Etag in their attempt to fix the supercookie problem (https://blog.mozilla.org/security/2021/01/26/supercookie-protections/)? oof

stoically avatar Feb 05 '21 13:02 stoically