[tor-bugs] #33625 [Applications/Tor Browser]: Disallow usage of Tor Browser until it is determined that the version is not the most recent

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 16 12:36:21 UTC 2020


#33625: Disallow usage of Tor Browser until it is determined that the version is
not the most recent
-------------------------+------------------------------------------
 Reporter:  cypherpunks  |          Owner:  tbb-team
     Type:  defect       |         Status:  new
 Priority:  Medium       |      Component:  Applications/Tor Browser
  Version:               |       Severity:  Blocker
 Keywords:               |  Actual Points:
Parent ID:               |         Points:
 Reviewer:               |        Sponsor:
-------------------------+------------------------------------------
 It is currently possible to use TB before and while downloading update. It
 is a grave security risk in case of 1-days.

 It is proposed to disallow navigation in the following cases:
 1 update is available, containing vulnerabilities fixes, but not yet
 installed. In this case update downloading progress should be displayed
 and the list of vulnerabilities fixed in the update.
 2 It is unknown whether update is available.

 In all cases the message must contain some text explaining why it is
 important to wait until the update process is finished.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/33625>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list