[tor-bugs] #10002 [Website]: Decide how to handle TBB 3.0beta download links and signature instructions

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Oct 31 01:39:59 UTC 2013


#10002: Decide how to handle TBB 3.0beta download links and signature instructions
---------------------------+-----------------------
     Reporter:  mikeperry  |      Owner:  mikeperry
         Type:  task       |     Status:  new
     Priority:  normal     |  Milestone:
    Component:  Website    |    Version:
   Resolution:             |   Keywords:
Actual Points:             |  Parent ID:
       Points:             |
---------------------------+-----------------------

Comment (by phobos):

 I guess step 1 in our instructions for using Tor is to switch to a
 properly free operating system, and then proceed further.

 In reality, we cannot get a code-signing certificate as Tor Project.  I've
 tried with Digicert and Thawte so far. In both cases, they want a landline
 "office phone number", proof of telephone bill in Tor's name, and our
 phone number listed in a 3rd party addressbook (such as the yellow pages).
 Apparently this is "best practice" for all code-signing certificates, and
 all of the various CAs agreed to this nonsense in some meeting of the
 cabal.

 Thawte did offer an alternative which was that I *personally* take on
 responsibility for the cert, but they'd issue it in Tor's name. It only
 required a notarized letter and proof of my identity.

 Maybe we should ask the comodo hacker to generate a code-signing cert for
 us....I'm kidding....

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10002#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list