[tbb-bugs] #17091 [Tor Browser]: Support our own hotfix mechanism

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Sep 16 00:16:50 UTC 2015


#17091: Support our own hotfix mechanism
--------------------------+--------------------------
 Reporter:  mikeperry     |          Owner:  tbb-team
     Type:  defect        |         Status:  new
 Priority:  normal        |      Milestone:
Component:  Tor Browser   |        Version:
 Keywords:  tbb-security  |  Actual Points:
Parent ID:                |         Points:
--------------------------+--------------------------
 We disabled the Firefox Hotfix system in #16837 over concerns about
 compatibility/conflicts.

 We can enable this again by setting extensions.hotfix.url to our own
 servers, and only pushing out a specific Mozilla hotfix after we've tested
 it on TBB ourselves, but then we need to deal with pinning and other
 issues. The pinning for AMO is specified here:
 https://mxr.mozilla.org/mozilla-
 central/source/security/manager/tools/PreloadedHPKPins.json#201

 Mozilla is also planning on replacing the Hotfix mechanism at some point,
 so we'll need to watch for falling bits.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17091>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list