Opened 6 years ago

Last modified 20 months ago

#13065 new defect

counter downgrade / stale mirror attacks on RecommendedTBBVersions - sign / verify tbb versions file

Reported by: proper Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-security, tbb-update
Cc: gk Actual Points:
Parent ID: #3893 Points:
Reviewer: Sponsor:

Description

Securely downloading https://www.torproject.org/projects/torbrowser/RecommendedTBBVersions solely relies on SSL, is currently neither signed, nor gets verified by Tor Button.

This is problematic, because should torproject.org's web server or CA be compromised one day, applications such as Tor Button and torbrowser-launcher could be fooled into using an outdated and/or malicious RecommendedTBBVersions file.

Suggestion: could you please,
1) provide a signed version of RecommendedTBBVersions,
2) verify RecommendedTBBVersions in Tor Button.

To prevent downgrade and stale mirror attacks, the signature would have to be renewed after every X weeks, and rejected by the verification mechanism [+ user notification] if is is too old. (Similar to Valid-Until / #9810.)

Child Tickets

Change History (4)

comment:1 Changed 6 years ago by gk

Cc: gk added
Keywords: tbb-security added

comment:2 Changed 3 years ago by teor

Severity: Normal

Set all open tickets without a severity to "Normal"

comment:3 Changed 2 years ago by traumschule

Parent ID: #3893

comment:4 Changed 20 months ago by gk

Keywords: tbb-update added

Adding update keyword

Note: See TracTickets for help on using tickets.