[tor-bugs] #5913 [Tor bundles/installation]: Check hashes for the packages downloaded during TBB build
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Thu May 17 18:27:02 UTC 2012
#5913: Check hashes for the packages downloaded during TBB build
--------------------------------------+-------------------------------------
Reporter: amieiro | Owner: erinn
Type: enhancement | Status: new
Priority: normal | Milestone:
Component: Tor bundles/installation | Version:
Keywords: | Parent:
Points: | Actualpoints:
--------------------------------------+-------------------------------------
I've added some steps to verify the sha256 hash of the downloaded
packages.
There's some more work to be done, mainly allowing for an easier way to
update the expected hashes (for now we should do this manually when we
update the package version) and for verifying gpg signatures, but this
should be an improvement over what we have now.
The patch is in the 'check_download_hashes' branch of
git://github.com/flavioamieiro/torbrowser.git
(https://github.com/flavioamieiro/torbrowser/tree/check_download_hashes).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5913>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list