[tor-talk] Unsigned Mac OS X binary for TorBrowser

Fabio Pietrosanti (naif) lists at infosecurity.ch
Sat Nov 10 14:57:04 UTC 2012


On 11/10/12 12:49 PM, Peter Tonoli wrote:
>
> On 10/11/12 6:49 PM, Fabio Pietrosanti (naif) wrote
>
> > Whatever apple would try to do against Tor Project, Apple will have to
> > sue me or ask me their rights! :P
> Or they could just revoke your developer certificate, and cause a lot of
> grief for the users of tor that has been signed with your certificate,
> as it will no longer run. This also probably wouldn't give tor a
> terribly good reputation either for reliability..
If Apple decide to revoke your developer certificate, you don't have
anything that you can do, regardless who is the "Formal owner" of the
developer certificate.

In any case, if you don't bother to use "Apple signature" as
identification system, you may just ask several trust-able organizations
(EFF, NoiseBridge, CCC, TorServers, etc) to apply for a Developer
Certificate and then provide it for free to Tor Project Inc.

That way Tor Project Inc would not have any kind of legal liability or
contractual relationship with Apple Corp, and you fixed the problem.

Fabio


More information about the tor-talk mailing list