[tor-bugs] #5463 [BridgeDB]: BridgeDB must GPG-sign outgoing mails

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Sat Mar 24 01:41:14 UTC 2012


#5463: BridgeDB must GPG-sign outgoing mails
----------------------+-----------------------------------------------------
 Reporter:  rransom   |          Owner:     
     Type:  defect    |         Status:  new
 Priority:  critical  |      Milestone:     
Component:  BridgeDB  |        Version:     
 Keywords:            |         Parent:     
   Points:            |   Actualpoints:     
----------------------+-----------------------------------------------------
 To protect users against attacks in which someone forges an e-mail message
 which appears to be sent by BridgeDB, but which contains malicious bridges
 intended to target a specific user, BridgeDB must start GPG-signing its
 outgoing e-mail messages.

 BridgeDB must also include the address to which it sent a message in the
 GPG-signed text, and warn users that they should verify that BridgeDB
 messages are GPG-signed and that the e-mail address in the signed message
 matches the e-mail address which the user requested bridges with.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5463>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list