[tor-bugs] #5463 [BridgeDB]: BridgeDB must GPG-sign outgoing mails
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Sat Mar 24 01:41:14 UTC 2012
#5463: BridgeDB must GPG-sign outgoing mails
----------------------+-----------------------------------------------------
Reporter: rransom | Owner:
Type: defect | Status: new
Priority: critical | Milestone:
Component: BridgeDB | Version:
Keywords: | Parent:
Points: | Actualpoints:
----------------------+-----------------------------------------------------
To protect users against attacks in which someone forges an e-mail message
which appears to be sent by BridgeDB, but which contains malicious bridges
intended to target a specific user, BridgeDB must start GPG-signing its
outgoing e-mail messages.
BridgeDB must also include the address to which it sent a message in the
GPG-signed text, and warn users that they should verify that BridgeDB
messages are GPG-signed and that the e-mail address in the signed message
matches the e-mail address which the user requested bridges with.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5463>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list