[tor-bugs] #19909 [Applications/Tor Browser]: Think about switching to Balrog for our server side Tor Browser update components

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Jan 8 10:07:51 UTC 2020


#19909: Think about switching to Balrog for our server side Tor Browser update
components
--------------------------------------+--------------------------
 Reporter:  gk                        |          Owner:  tbb-team
     Type:  task                      |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by gk):

 Balrog has capbability for throttling updates, which is interesting for
 moving to a regular release channel. Background: https://hearsum.ca/blog
 /streamlining-throttled-rollout-of-firefox-releases.html. Bug:
 https://bugzilla.mozilla.org/show_bug.cgi?id=1246675.

 Additionally, there might be ways to harden our update infrastructure
 against at least some attacks by having multiple sign-off requirements for
 update pushes. Background: https://hearsum.ca/blog/rings-of-power-
 multiple-signoff-in-balrog.html. Bug:
 https://bugzilla.mozilla.org/show_bug.cgi?id=1278974.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/19909#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list