[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-bugs] #17091 [Tor Browser]: Support our own hotfix mechanism



#17091: Support our own hotfix mechanism
--------------------------+--------------------------
 Reporter:  mikeperry     |          Owner:  tbb-team
     Type:  defect        |         Status:  new
 Priority:  normal        |      Milestone:
Component:  Tor Browser   |        Version:
 Keywords:  tbb-security  |  Actual Points:
Parent ID:                |         Points:
--------------------------+--------------------------
 We disabled the Firefox Hotfix system in #16837 over concerns about
 compatibility/conflicts.

 We can enable this again by setting extensions.hotfix.url to our own
 servers, and only pushing out a specific Mozilla hotfix after we've tested
 it on TBB ourselves, but then we need to deal with pinning and other
 issues. The pinning for AMO is specified here:
 https://mxr.mozilla.org/mozilla-
 central/source/security/manager/tools/PreloadedHPKPins.json#201

 Mozilla is also planning on replacing the Hotfix mechanism at some point,
 so we'll need to watch for falling bits.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17091>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs