[tor-bugs] #13379 [Tor Browser]: Sign our MAR files

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Nov 10 20:20:03 UTC 2014


#13379: Sign our MAR files
-----------------------------+--------------------------
     Reporter:  mikeperry    |      Owner:  tbb-team
         Type:  defect       |     Status:  new
     Priority:  major        |  Milestone:
    Component:  Tor Browser  |    Version:
   Resolution:               |   Keywords:  tbb-security
Actual Points:               |  Parent ID:
       Points:               |
-----------------------------+--------------------------

Comment (by gk):

 While thinking about comment:10:ticket:13407 and that it probably is wise
 to "just" have a role signing key due to just one key for verifying our
 MARs I was wondering whether it would be feasible to take advantage of
 reproducibly built MAR files given that no human interaction is
 interfering here. This is definitely worth a new bug if it is worth one at
 all (and I am volunteering for coding this actually). Given your knowledge
 of the MAR signing code Mozilla provides do you think there are general
 obstacles to extend that to add support for a verification method relying
 on more than one key?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13379#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list