[tor-talk] automatic Tor browser updates

Georg Koppen gk at torproject.org
Mon Feb 8 08:36:53 UTC 2016


Mirimir:
> When automatically updating, does Tor browser check GPG signatures of
> downloaded updates before installing them?

The update files are not using GPG signatures (see:
https://wiki.mozilla.org/Software_Update:MAR for detailed information
about the MAR file format). They are signed, though, and the updater
refuses to install the update if the signature is non-existing or wrong.

Georg


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: OpenPGP digital signature
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20160208/3ff0d231/attachment-0001.sig>


More information about the tor-talk mailing list