Closed
Bug 525786
Opened 15 years ago
Closed 15 years ago
Weave's log has a record of private browsing start/stop times
Categories
(Cloud Services :: General, defect)
Tracking
(Not tracked)
RESOLVED
FIXED
1.0 beta2
People
(Reporter: dholbert, Assigned: Mardak)
References
Details
Currently, Weave's "activity log" records all entrances & exits from Private Browsing mode.
This looks like the following in my Weave Activity Log:
> 2009-11-01 15:45:58 Service.Main DEBUG Private browsing change: enter
> 2009-11-01 15:46:00 Service.Main DEBUG Private browsing change: exit
IMHO, this is a breach of the spirit of Private Browsing Mode. Expected behavior is that no traces of my Private Browsing should remain.
With current behavior, an adversary could examine a Firefox profile and tell exactly when and for how long a Weave user has used Private Browsing mode... and that could be potentially incriminating.
Reporter | ||
Comment 1•15 years ago
|
||
FWIW, I'm using: Weave 0.8pre3 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.3a1pre) Gecko/20091101 Minefield/3.7a1pre Steps to reproduce (if they aren't already obvious): 1. Enter Private Browsing mode (Ctrl+Shift+P) 2. Exit Private Browsing mode (Ctrl+Shift+P) 3. Examine the end of your Weave Activity log (click Weave icon in status bar, and choose "Activity Log") --> you'll see two lines like those quoted in comment 0.
Reporter | ||
Comment 2•15 years ago
|
||
(In reply to comment #0) > IMHO, this is a breach of the spirit of Private Browsing Mode. Expected > behavior is that no traces of my Private Browsing should remain. ...including any signs of the fact that Private Browsing was used at all.
Assignee | ||
Comment 3•15 years ago
|
||
If we remove those debug lines, the log will look something like... 2009-11-04 17:20:17 Service.Main DEBUG Next sync in 83173 sec. 2009-11-04 17:20:28 Service.Main DEBUG Next sync in 83162 sec. where those 2 lines are 2 *exit*s from private browsing. So.. it doesn't say when you entered private browsing, but a random "next sync in ..." without any other text might indicate an exit from private browsing.
Assignee | ||
Comment 4•15 years ago
|
||
I suppose if we remove the debug lines for network offline change, it could totally look like you just had a network hiccup ;)
Assignee | ||
Comment 5•15 years ago
|
||
http://hg.mozilla.org/labs/weave/rev/96f92f159d10 Switch some messages like private browsing, network change to trace and make the default service.main level Debug instead of Trace.
Assignee: nobody → edilee
Status: NEW → RESOLVED
Closed: 15 years ago
Resolution: --- → FIXED
Target Milestone: --- → 1.0 beta2
Assignee | ||
Updated•15 years ago
|
Target Milestone: 1.0 beta3 → 1.0 beta2
Comment 6•14 years ago
|
||
Investigating this bug for being potential crossweave automation test case candidate.
Flags: in-testsuite?
You need to log in
before you can comment on or make changes to this bug.
Description
•