Opened 3 years ago

Closed 3 years ago

#20189 closed enhancement (worksforme)

MAR files should be signed with a modern signature algorithm.

Reported by: yawning Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Mostly theoretical, and may be just a case of out of date upstream documentation.

https://wiki.mozilla.org/Software_Update:MAR

1: RSA-PKCS1-SHA1 (2048 bits / 256 bytes)

We should patch the MAR related code to add something more suitable to our adversary model, though what's used now should be "adequate" for the near term future.

Child Tickets

Change History (1)

comment:1 Changed 3 years ago by mcs

Resolution: worksforme
Status: newclosed
Note: See TracTickets for help on using tickets.