I've also noticed cookies persisting after using 'New Tor Circuit...' and it was (for me) unexpected behaviour. I think this is dangerous because people may assume it also resets the browser state for that site.

One solution is to make 'New Circuit...' delete cookies etc, so that it behaves as expected.

Another is to somehow make it clearer that sessions etc persist when using 'New Circuit..' so that people aren't getting a false sense of security.

Either is fine, but the status quo is unsafe.

Reply

  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <em> <strong> <cite> <code> <ul> <ol> <li> <b> <i> <strike> <p> <br>

More information about formatting options

Syndicate content