[tbb-bugs] #19121 [Applications/Tor Browser]: reinstate the update.xml hash check

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu May 19 15:00:06 UTC 2016


#19121: reinstate the update.xml hash check
-------------------------------------+-------------------------------------
     Reporter:  mcs                  |      Owner:  tbb-team
         Type:  defect               |     Status:  new
     Priority:  Medium               |  Milestone:
    Component:  Applications/Tor     |    Version:
  Browser                            |   Keywords:  ff45-esr,
     Severity:  Normal               |  TorBrowserTeam201605, tbb-6.0-must
Actual Points:                       |  Parent ID:
       Points:                       |   Reviewer:
      Sponsor:                       |
-------------------------------------+-------------------------------------
 While working on #18912, Kathy and I discovered the following Mozilla
 change that causes the update.xml hash check to be skipped when signed MAR
 files are in use (this change shipped in Firefox 43):
 https://bugzilla.mozilla.org/show_bug.cgi?id=862173

 I think the our philosophy is different than Mozilla's and that we
 probably want to reinstate the hash check. Mike and Georg, do you agree?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/19121>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list