[tor-talk] Possibly Smart, Possibly Stupid, Idea Regarding Tor & Linux Distributions

Jeremy Rand jeremyrand at airmail.cc
Sun Jan 8 04:50:23 UTC 2017


Alec Muffett:
> In my previous e-mail I suggested removing Tor from Debian precisely
> because of this future-staleness problem.
> 
> I still believe that this is a decent idea, because stale code sucks.
> 
> Another possible solution would be creation of a "Tor Server Bundle" -
> designed and maintained to run successfully on most major platforms, it
> would be a bunch of scripts that find existing, stale versions of Tor, kill
> and remove them, and migrate the platform to a more recent version, with
> *optional* enabling of auto-updating because you will want to have a stable
> environment. :-P
> 
> And it would (ideally) also ship with some portable, stupid but bombproof,
> interactive and scriptable CLI wizards for setting up Onion services.

I won't claim to know whether this is a good idea, but one other option
is to only have Tor in Debian Sid.  My understanding is that this is
already done for some Bitcoin-related software, because the Bitcoin
packagers refused to guarantee that their packages would work through
testing/stable's lifespans (due to the chance that consensus forks will
break old clients, which has happened before and could easily happen
again).  It seems plausible that a similar path could work for Tor.

Cheers,
-Jeremy

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: OpenPGP digital signature
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20170108/e4f0b6a3/attachment.sig>


More information about the tor-talk mailing list