[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-talk] Verifying signatures



On 03/21/2012 12:46 PM, Jude Young wrote:
> Sorry if this has been responded to, I've lost a few emails...
> I don't believe the TBB has been high-jacked, but the TorButton Firefox
> extension certainly has.
> (Forgive my faulty memory 
> linky:http://www.securitynewsdaily.com/1201-anonymous-hackers-child-porn.html)
> "Anonymous" apparently convinced firefox (or someone at FireFox? No one was
> ever clear on this..) to upload a modified version.

Uh, TorButton is free software, didn't you know that? Everybody can create
and distribute a modified version, and that's what happened. It certainly
proves that you shouldn't download software from untrusted sources (neither
the Tor Project nor Mozilla was involved) and that you should verify the
signatures of the software to use. None of that is news, of course.

Best regards
	Christian

-- 
|------- Dr. Christian Siefkes ------- christian@xxxxxxxxxxx -------
| Homepage: http://www.siefkes.net/ | Blog: http://www.keimform.de/
|    Peer Production Everywhere:       http://peerconomy.org/wiki/
|---------------------------------- OpenPGP Key ID: 0x346452D8 --
Progress isn't made by early risers. It's made by lazy men trying to find
easier ways to do something.
        -- Robert Heinlein

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
tor-talk mailing list
tor-talk@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk