[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-bugs] #5463 [BridgeDB]: BridgeDB must GPG-sign outgoing mails



#5463: BridgeDB must GPG-sign outgoing mails
----------------------+-----------------------------------------------------
 Reporter:  rransom   |          Owner:     
     Type:  defect    |         Status:  new
 Priority:  critical  |      Milestone:     
Component:  BridgeDB  |        Version:     
 Keywords:            |         Parent:     
   Points:            |   Actualpoints:     
----------------------+-----------------------------------------------------
 To protect users against attacks in which someone forges an e-mail message
 which appears to be sent by BridgeDB, but which contains malicious bridges
 intended to target a specific user, BridgeDB must start GPG-signing its
 outgoing e-mail messages.

 BridgeDB must also include the address to which it sent a message in the
 GPG-signed text, and warn users that they should verify that BridgeDB
 messages are GPG-signed and that the e-mail address in the signed message
 matches the e-mail address which the user requested bridges with.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5463>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs