[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-bugs] #5463 [BridgeDB]: BridgeDB must GPG-sign outgoing mails
#5463: BridgeDB must GPG-sign outgoing mails
----------------------+-----------------------------------------------------
Reporter: rransom | Owner:
Type: defect | Status: new
Priority: critical | Milestone:
Component: BridgeDB | Version:
Keywords: | Parent:
Points: | Actualpoints:
----------------------+-----------------------------------------------------
To protect users against attacks in which someone forges an e-mail message
which appears to be sent by BridgeDB, but which contains malicious bridges
intended to target a specific user, BridgeDB must start GPG-signing its
outgoing e-mail messages.
BridgeDB must also include the address to which it sent a message in the
GPG-signed text, and warn users that they should verify that BridgeDB
messages are GPG-signed and that the e-mail address in the signed message
matches the e-mail address which the user requested bridges with.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5463>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs