[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #13379 [Tor Browser]: Sign our MAR files
#13379: Sign our MAR files
-----------------------------+--------------------------
Reporter: mikeperry | Owner: tbb-team
Type: defect | Status: new
Priority: major | Milestone:
Component: Tor Browser | Version:
Resolution: | Keywords: tbb-security
Actual Points: | Parent ID:
Points: |
-----------------------------+--------------------------
Comment (by gk):
While thinking about comment:10:ticket:13407 and that it probably is wise
to "just" have a role signing key due to just one key for verifying our
MARs I was wondering whether it would be feasible to take advantage of
reproducibly built MAR files given that no human interaction is
interfering here. This is definitely worth a new bug if it is worth one at
all (and I am volunteering for coding this actually). Given your knowledge
of the MAR signing code Mozilla provides do you think there are general
obstacles to extend that to add support for a verification method relying
on more than one key?
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13379#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs