Opened 5 years ago

Last modified 4 months ago

#13065 new defect

counter downgrade / stale mirror attacks on RecommendedTBBVersions - sign / verify tbb versions file

Reported by: proper Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-security, tbb-update
Cc: gk Actual Points:
Parent ID: #3893 Points:
Reviewer: Sponsor:

Description

Securely downloading https://www.torproject.org/projects/torbrowser/RecommendedTBBVersions solely relies on SSL, is currently neither signed, nor gets verified by Tor Button.

This is problematic, because should torproject.org's web server or CA be compromised one day, applications such as Tor Button and torbrowser-launcher could be fooled into using an outdated and/or malicious RecommendedTBBVersions file.

Suggestion: could you please,
1) provide a signed version of RecommendedTBBVersions,
2) verify RecommendedTBBVersions in Tor Button.

To prevent downgrade and stale mirror attacks, the signature would have to be renewed after every X weeks, and rejected by the verification mechanism [+ user notification] if is is too old. (Similar to Valid-Until / #9810.)

Child Tickets

Change History (4)

comment:1 Changed 5 years ago by gk

Cc: gk added
Keywords: tbb-security added

comment:2 Changed 19 months ago by teor

Severity: Normal

Set all open tickets without a severity to "Normal"

comment:3 Changed 10 months ago by traumschule

Parent ID: #3893

comment:4 Changed 4 months ago by gk

Keywords: tbb-update added

Adding update keyword

Note: See TracTickets for help on using tickets.