[tor-bugs] #22205 [Applications/Tor Browser Sandbox]: Figure out how to fix `crypto/tls`.

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue May 9 02:35:56 UTC 2017


#22205: Figure out how to fix `crypto/tls`.
----------------------------------------------+-------------------------
 Reporter:  yawning                           |          Owner:  yawning
     Type:  defect                            |         Status:  new
 Priority:  Medium                            |      Milestone:
Component:  Applications/Tor Browser Sandbox  |        Version:
 Severity:  Normal                            |     Resolution:
 Keywords:                                    |  Actual Points:
Parent ID:                                    |         Points:
 Reviewer:                                    |        Sponsor:
----------------------------------------------+-------------------------

Comment (by yawning):

 Since we attempt to play nice and use the CDN for downloads, any tweaks to
 the cipher suite list need to take what the CDN runs into account.  A
 quick check suggests that at least `aus1.torproject.org` does not support
 `
 `TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305` or
 `TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305`, though most accesses to that
 particular host will be via the onion sans-TLS, so it matters the least.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22205#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list