Hi!
Tor Browser 8.5a6 is ready for testing. Bundles can be found at:
https://people.torproject.org/~boklm/builds/8.5a6-build1/
This new Tor Browser version picks up Firefox security bug fixes coming
with Firefox 60.4.0esr and upgrades OpenSSL 1.0.2q.
The most exciting news, however, compared to the release earlier this
week comes from progress we made on our mobile builds. Tor Browser 8.5a6
is the first version that is built reproducibly and is localized in all
locales the desktop platforms support.
Moreover, we added an updated donation banner for our year-end donation
campaign.
Known issues: On newer Android versions (Android 7+) downloading a file
is crashing Tor Browser. This is tracked in
https://trac.torproject.org/projects/tor/ticket/28705 and we plan to
have a fix available in Tor Browser 8.5a7. Sorry for the inconvenience.
The full changelog since 8.5a5 is:
Tor Browser 8.5a6 -- December 11 2018
* All Platforms
* Update Firefox to 60.4.0esr
* Update OpenSSL to 1.0.2q
* Update Torbutton to 2.1.3
* Bug 28540: Use new text for 2018 donation banner
* Bug 27290: Remove WebGL pref for min capability mode
* Bug 28075: Tone down missing SOCKS credential warning
* Bug 28747: Remove NoScript (XPCOM) related unused code
* Translations update
* Bug 28608: Disable background HTTP response throttling
* Bug 28695: Set default security.pki.name_matching_mode to enforce (3)
* Bug 27290: Remove WebGL pref for min capability mode
* Bug 27919: Backport SSL status API
* Windows
* Bug 28740: Adapt Windows navigator.platform value on 64-bit systems
* Android
* Bug 26843: Multi-locale support for Tor Browser on Android
* Build System
* Android
* Bug 25164: Add .apk to our sha256sums unsigned build file
* Bug 28696: Make path to Gradle dependencies reproducible
* Bug 28697: Use pregenerated keystore and fix timestamp issues
Georg
Hello everyone!
We are happy to announce that Tor Browser 8.0.4 is ready for testing.
Bundles can be found at
https://people.torproject.org/~boklm/builds/8.0.4-build2/
This new Tor Browser version contains updates to Tor (0.3.4.9), OpenSSL
(1.0.2q) and other bundle components. Most importantly, however, it is
based on Firefox 60.4.0esr containing fixes to Firefox security bugs.
We backported a number of patches from our alpha series where they got
some baking time. The most important ones are
1) a defense against protocol handler enumeration which should enhance
our fingerprinting resistance,
2) enabling Stylo for macOS users by bypassing a reproducibility issue
caused by Rust compilation and
3) setting back the sandboxing level on 5 Windows (the default), after
working around some Tor Launcher interference causing a broken Tor
Browser experience.
Additionally, we ship an updated donation banner for our year-end
donation campaign.
The full changelog since 8.0.3 is:
Tor Browser 8.0.4 -- December 11 2018
* All platforms
* Update Firefox to 60.4.0esr
* Update Tor to 0.3.4.9
* Update OpenSSL to 1.0.2q
* Update Torbutton to 2.0.9
* Bug 28540: Use new text for 2018 donation banner
* Bug 28515: Use en-US for english Torbutton strings
* Translations update
* Update HTTPS Everywhere to 2018.10.31
* Update NoScript to 10.2.0
* Bug 1623: Block protocol handler enumeration (backport of fix for
#680300)
* Bug 25794: Disable pointer events
* Bug 28608: Disable background HTTP response throttling
* Bug 28185: Add smallerRichard to Tor Browser
* Windows
* Bug 26381: about:tor page does not load on first start on Windows
* Bug 28657: Remove broken FTE bridge from Tor Browser
* OS X
* Bug 26263: App icon positioned incorrectly in macOS DMG installer
window
* Bug 26475: Fix Stylo related reproducibilitiy issue
* Linux
* Bug 26475: Fix Stylo related reproducibilitiy issue
* Bug 28657: Remove broken FTE bridge from Tor Browser
* Build System
* All Platforms
* Bug 27218: Generate multiple Tor Browser bundles in parallel
Georg
Hi all!
We are pleased to announce that Tor Browser 8.5a5 is ready for testing.
Bundles can be found at:
https://people.torproject.org/~boklm/builds/8.5a5-build2/
We included a new Tor alpha version in the desktop bundles
(0.3.5.5-alpha) to help stabilizing the networking code. Furthermore, we
managed to fix two longstanding first party isolation bugs: Both PDF
range requests[1] and saving links, images or similar using the context
menu[2] are now properly isolated to the URL bar domain.
Most importantly, though, we reached another milestone in our efforts to
bring Tor Browser for Android into stable shape. From now on it is not
necessary anymore to download Orbot in order to use Tor Browser. We
implemented a similar solution to our desktop Tor Browser flavors by
shipping and using Orbot in Tor Browser directly.[3] We plan to refine
our approach for an even smoother user exprience in the future, so stay
tuned.[4][5] Additionally, we included the mobile build into our
official Tor Browser build infrastructure, implying a similar versioning
scheme and same day releases starting with the alpha series. The build
artifacts are not reproducible yet (although we are pretty close
reaching that goal).[6] But fixing that is one of the top priorities for
our next big milestone for the Android app.
Below are all changes listed since Tor Browser 8.5a4 and the previous
alpha release for Android:
Tor Browser 8.5a5 -- December 3 2018
* All Platforms
* Update Torbutton to 2.1.2
* Bug 25013: Integrate Torbutton into tor-browser for Android
* Bug 27111: Update about:tor desktop version to work on mobile
* Bug 28093: Update donation banner style to make it fit in small
screens
* Bug 28543: about:tor has scroll bar between widths 900px and 1000px
* Bug 28039: Enable dump() if log method is 0
* Bug 27701: Don't show App Blocker dialog on Android
* Bug 28187: Change tor circuit icon to torbutton.svg
* Bug 28515: Use en-US for english Torbutton strings
* Translations update
* Update Tor Launcher to 0.2.18
* Bug 28039: Enable dump() if log method is 0
* Translations update
* Update HTTPS Everywhere to 2018.10.31
* Update NoScript to 10.2.0
* Bug 22343: Make 'Save Page As' obey first-party isolation
* Bug 26540: Enabling pdfjs disableRange option prevents pdfs from
loading
* Windows
* Update Tor to 0.3.5.5-alpha
* Bug 28310: Don't build obfs4 with module versioning support
* Bug 27827: Update Go to 1.11.1
* Bug 28185: Add smallerRichard to Tor Browser
* Bug 28657: Remove broken FTE bridge from Tor Browser
* OS X
* Update Tor to 0.3.5.5-alpha
* Bug 28310: Don't build obfs4 with module versioning support
* Bug 27827: Update Go to 1.11.1
* Bug 27827: Build snowflake reproducibly
* Bug 28258: Don't look for webrtc headers under talk/
* Bug 28185: Add smallerRichard to Tor Browser
* Linux
* Update Tor to 0.3.5.5-alpha
* Bug 28310: Don't build obfs4 with module versioning support
* Bug 27827: Update Go to 1.11.1
* Bug 27827: Build snowflake reproducibly
* Bug 28258: Don't look for webrtc headers under talk/
* Bug 28185: Add smallerRichard to Tor Browser
* Bug 28657: Remove broken FTE bridge from Tor Browser
* Android
* Bug 28051: Fix up Orbot for inclusion into Tor Browser
* Bug 26690+25765: Port padlock states for .onion serices to mobile
* Bug 28507: Delete private data in the browser startup
* Bug 27111+25013: Configure Tor Browser for mobile to load about:tor
* Bug 27256: Enable TouchEvents on Android
* Bug 28640: Use system add-on and distributed preferences
* Build System
* Bug 27977: Build Orbot inside tor-browser-build
* Bug 27443: Update Firefox RBM config and build for Android
* Bug 27439: Add android target for rust compiler
* Bug 28469: Fix unsupported libbacktrace in Rust 1.26
* Bug 28468: Modify Android toolchain to support Orbot
* Bug 28483: Modify Android Toolchain API Version
* Bug 28472: Add Android Makefile Rules
* Bug 28470: Add fetch gradle dependency script to common project
* Bug 28144: Update projects/tor-browser for Android
Georg
[1] https://trac.torproject.org/projects/tor/ticket/26540
[2] https://trac.torproject.org/projects/tor/ticket/22343
[3] https://trac.torproject.org/projects/tor/ticket/28051
[4] https://trac.torproject.org/projects/tor/ticket/28329
[5] https://trac.torproject.org/projects/tor/ticket/27609
[6] https://trac.torproject.org/projects/tor/ticket/25164