[tor-bugs] #9810 [Tor Sysadmin Team]: use Valid-Until field to prevent downgrade attacks for deb.torproject.org

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Sep 23 23:55:45 UTC 2013


#9810: use Valid-Until field to prevent downgrade attacks for deb.torproject.org
-------------------------------+------------------------
 Reporter:  proper             |          Owner:  weasel
     Type:  defect             |         Status:  new
 Priority:  normal             |      Milestone:
Component:  Tor Sysadmin Team  |        Version:
 Keywords:                     |  Actual Points:
Parent ID:                     |         Points:
-------------------------------+------------------------
 To prevent downgrade and stale mirror attacks against deb.torproject.org,
 please use the [http://blog.ganneff.de/blog/2008/09/23/valid-until-field-
 in-release-f.html Valid-Until] field.

 Since you are using reprepro, you can add in your conf/distributions file

 {{{
 ValidFor: 2w
 }}}

 (Or ValidFor: 4w or 1m.) under every instance of "Label:" or so.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9810>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list