[tor-bugs] #10943 [Tor Messenger]: Sandboxing Instantbird

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Jul 21 21:04:47 UTC 2015


#10943: Sandboxing Instantbird
-------------------------------+------------------------------------------
     Reporter:  sukhbir        |      Owner:  ioerror
         Type:  task           |     Status:  new
     Priority:  normal         |  Milestone:
    Component:  Tor Messenger  |    Version:
   Resolution:                 |   Keywords:  SponsorO, TorMessengerPublic
Actual Points:                 |  Parent ID:
       Points:                 |
-------------------------------+------------------------------------------

Comment (by ioerror):

 We should ensure that we review the build process to make it both
 deterministic and to ensure that we enable all of the relevant hardening
 options.

 Furthermore, I'd like to point out that while not exactly sandboxing, we
 should build any relevant Instantbird component with ASan:
 https://www.chromium.org/developers/testing/addresssanitizer - this means
 that on OSX and GNU/Linux, we should be doing 64bit builds. My suggestion
 would be to produce only 64bit builds that meet our security expectations.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10943#comment:7>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list