[tor-bugs] #10096 [Tor bundles/installation]: Verify language packs after downloading them when building with Gitian

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Nov 4 12:26:34 UTC 2013


#10096: Verify language packs after downloading them when building with Gitian
--------------------------------------+-----------------------
 Reporter:  gk                        |          Owner:  erinn
     Type:  enhancement               |         Status:  new
 Priority:  normal                    |      Milestone:
Component:  Tor bundles/installation  |        Version:
 Keywords:  tbb-3.0, gitian           |  Actual Points:
Parent ID:                            |         Points:
--------------------------------------+-----------------------
 We should verify that we actually get the language packs we really want to
 get when running the fetch-inputs script. That serves two purposes: 1) it
 is a defense in depth against attackers that may be able to modify the
 contents of the language pack but don't own Mozilla's signing key 2) We
 may avoid problems with old language packs that somehow slipped in just
 before starting a new TBB build.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10096>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list