[tor-bugs] #10943 [Tor Messenger]: Sandboxing Instantbird

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Jul 21 20:56:27 UTC 2015


#10943: Sandboxing Instantbird
-------------------------------+------------------------------------------
     Reporter:  sukhbir        |      Owner:  ioerror
         Type:  task           |     Status:  new
     Priority:  normal         |  Milestone:
    Component:  Tor Messenger  |    Version:
   Resolution:                 |   Keywords:  SponsorO, TorMessengerPublic
Actual Points:                 |  Parent ID:
       Points:                 |
-------------------------------+------------------------------------------

Comment (by ioerror):

 Sandboxing on OSX is probably the easiest.

 I think that we should consider using Arturo's BuckleUp for OS X
 sandboxing:

   https://github.com/hellais/Buckle-Up

 We should also consider the designs of Chrome:

   https://www.chromium.org/developers/design-documents/sandbox/osx-
 sandboxing-design

 We may also want to look at the profiles of other programs:

   https://github.com/s7ephen/OSX-Sandbox--Seatbelt--Profiles

 I think while this isn't exactly sandboxing, we should also put our app in
 the OS X App store. Distribution and updating is a security issue of the
 highest order - lets make sure the app is not only sandboxed but also
 signed, available without the appstore and in the appstore as well.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10943#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list