#6098: Add a hidden service to check.torproject.org
-----------------------+----------------------------------------------------
 Reporter:  proper     |          Owner:     
     Type:  defect     |         Status:  new
 Priority:  critical   |      Milestone:     
Component:  Tor Check  |        Version:     
 Keywords:             |         Parent:     
   Points:             |   Actualpoints:     
-----------------------+----------------------------------------------------
 TorBrowser gets it's version information from
 https://check.torproject.org/RecommendedTBBVersions and
 https://check.torproject.org/ is TBB's homepage.

 For an adversary, it's granted, that every user of Tor Browser will visit
 that page. It must be too tempting to MITM that site and to spread some
 malicious content.

 The SSL certificate authority system was recently compromised and is
 flawed by design. I suggest making check.torproject.org accessible through
 a hidden service.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/6098>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
[email protected]
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Reply via email to