[tor-bugs] #13407 [Tor bundles/installation]: Transition smoothly away from Erinn's signing key for the coming releases

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Oct 31 13:20:19 UTC 2014


#13407: Transition smoothly away from Erinn's signing key for the coming releases
------------------------------------------+--------------------------------
     Reporter:  gk                        |      Owner:  erinn
         Type:  task                      |     Status:  new
     Priority:  normal                    |  Milestone:
    Component:  Tor bundles/installation  |    Version:
   Resolution:                            |   Keywords:  security,
Actual Points:                            |  usability
       Points:                            |  Parent ID:
------------------------------------------+--------------------------------

Comment (by gk):

 As Mike noted today on IRC we are hopefully soon able to ship signed MAR
 files for the updater which means that it might not be worth all the fancy
 efforts in trying to safeguard a role signing key given that we need to
 include that one MAR signing key into our Tor Browser which creates yet
 another single point of failure... (granted I am simplifying a bit given
 the certificate pinning but still...).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13407#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list