Ticket Summary Owner Component Milestone
#25131 Add a security.txt file to Webpages/Website website redesign

security.txt files give people the information they need to contact Tor when they find a security issue.

It's an IETF draft, and Google has done it, so maybe we should too:

We can use the existing information at:

And we might want to:

  • add a PGP key file
  • add a signature
  • maybe add a policy or acknowledgements when we decide how they work
#25475 TB Credits traumschule Webpages/Website website redesign

We should have a page of contributors, either on the website or Tor browser. Tor Community members, translators etc

#26307 Add link to Tor SlackBuild on download-unix.html.en Webpages/Website website redesign

I thought it would be nice to add link to the Tor SlackBuild on download-unix.html.en. The SlackBuild works fine and is updated regularly.

The code would be something like this:

<tr class="beige">
<td align="center"><img src="$(IMGROOT)/distros/slackware.png" alt="Slackware"></td>
<td colspan="2"><a href=""></a></td>
<a href="<page docs/tor-doc-unix>">Linux/BSD/Unix</a><br>

If nobody wants to design a new logo, there's generic.png in /images/distros/ folder

#27421 Tor security policy Webpages/Website website redesign

Tor Project currently has not general security policy. We need to work out a security policy that covers all of Tor: See

#27423 Sign security.txt Webpages/Website website redesign

From comment:6:ticket:25131:

I suggest we use the tor-security list key, or some other key that many people trust.

#27458 security.txt: Add acknowledgments page to honour our security researches Webpages/Website website redesign

The page will be linked in

Details: ​ Basically a place to honour the work of former / current security researchers.

This could also go into #25475.

#29200 Make more accessible Core Tor documentation pili Webpages/Website website redesign

There's Core Tor documentation distributed in three (at least) sources. Even if it's documentation intended for developers, it'd be great that it would be more accessible by providing the HTML version online and using some subdomain or path or links. The sources are:

I can provide scripts to generate/convert the documentation automatically. We would need to decide where to put it, maybe get subdomain and get access to the server where it would live.

#30838 Update the Debian instructions for experimental-0.4.1 hiro Webpages/Website Tor: unspecified

The 0.4.1 branch is now separate; the 0.3.4 branches are now deprecated.

We should update the website accordingly:

This change requires the change in #30836, and a successful nightly build of experimental-0.4.1.

