Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How do you plan to keep torproject.pem updated? #45

Closed
adrelanos opened this issue May 24, 2013 · 2 comments
Closed

How do you plan to keep torproject.pem updated? #45

adrelanos opened this issue May 24, 2013 · 2 comments
Labels

Comments

@adrelanos
Copy link

As far I know, The Tor Project (tpo) has no mechanism to inform others when they are planing to change their SSL certificates. One day they might just replace it and torbrowser-launcher will break.

Do you think its worth asking tpo for their policy on that topic or if they could add such a policy? Other thoughts?

@micahflee
Copy link
Collaborator

Good question. I wonder if the cert pinning stuff adds unnecessary complexity considering that we already verify signatures. Of course, this isn't true when loading https://check.torproject.org/RecommendedTBBVersions. Also, cert pinning isn't even enabled if you choose to use a torproject.org mirror, and most of those are over http anyway.

Alternatively we could just update torproject.pem if it becomes an issue, and there will just be a small period of time where TBL doesn't work for people.

@micahflee
Copy link
Collaborator

Actually, I just updated torproject.pem when it became an issue. It took me way longer than it should have, but I think that it makes sense to continue to do this anyway (and I'll be more prompt). Either that or no cert pinning, but I prefer cert pinning.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants