[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-bugs] #6098 [Tor Check]: Add a hidden service to check.torproject.org
#6098: Add a hidden service to check.torproject.org
-----------------------+----------------------------------------------------
Reporter: proper | Owner:
Type: defect | Status: new
Priority: critical | Milestone:
Component: Tor Check | Version:
Keywords: | Parent:
Points: | Actualpoints:
-----------------------+----------------------------------------------------
TorBrowser gets it's version information from
https://check.torproject.org/RecommendedTBBVersions and
https://check.torproject.org/ is TBB's homepage.
For an adversary, it's granted, that every user of Tor Browser will visit
that page. It must be too tempting to MITM that site and to spread some
malicious content.
The SSL certificate authority system was recently compromised and is
flawed by design. I suggest making check.torproject.org accessible through
a hidden service.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/6098>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs