Hi,

In December, the Tor Browser team made 4 releases: 5.0.5[1], 5.0.6[2],
5.5a5[3], and 5.5a5-hardened[4].

The 5.0.5 stable release featured improvements in our fingerprinting
defenses[5][6], code for our donation campaign[7][8][9] and a
long-wanted fix for our circuit display[10]. Unfortunately, a follow-up
release, 5.0.6, was needed as Mozilla fixed another couple of serious
bugs in the final ESR 38.5.0 release based on the second candidate build
which we missed (we started using the first one)[11].

In the 5.5a5 release, we additionally cleaned up our about:tor
appearance[12], improved font and keyboard fingerprinting
defenses[13][14][15][16] and disabled the RC4 fallback option in TLS
connections[17]. Moreover, the changelog shown after an update is
generated locally now[18].

For 5.5a5-hardened, we compiled the Firefox part with -fwrapv guarding
against some type of undefined behavior[19]. Apart from that it contains
the same changes as 5.5a5.

The full list of tickets closed by the Tor Browser team in December can
be seen using the TorBrowserTeam201512 tag on our bug tracker[20].

In January, we plan to release 5.0.7, 5.5a6 and 5.5a6-hardened which are
out-of-bound releases fixing a potentially exploitable crash bug[21].
Apart from that we are focusing on getting Tor Browser 5.5 into a stable
shape and plan to release it by end of January. Work on our OS X
codesigning continues as well.

The full list of tickets the Tor Browser team plans to work on in
January can be seen with the TorBrowserTeam201601 tag on our bug
tracker[19].

Georg

[1] https://blog.torproject.org/blog/tor-browser-505-released
[2] https://blog.torproject.org/blog/tor-browser-506-released
[3] https://blog.torproject.org/blog/tor-browser-55a5-released
[4] https://blog.torproject.org/blog/tor-browser-55a5-hardened-released
[5] https://bugs.torproject.org/17207
[6] https://bugs.torproject.org/17446
[7] https://bugs.torproject.org/17565
[8] https://bugs.torproject.org/17770
[9] https://bugs.torproject.org/17792
[10] https://bugs.torproject.org/16990
[11] https://bugs.torproject.org/17877
[12] https://bugs.torproject.org/17108
[13] https://bugs.torproject.org/17759
[14] https://bugs.torproject.org/17661
[15] https://bugs.torproject.org/17250
[16] https://bugs.torproject.org/17009
[17] https://bugs.torproject.org/17369
[18] https://bugs.torproject.org/16940
[19] https://bugs.torproject.org/12516
[20]
https://trac.torproject.org/projects/tor/query?status=closed&keywords=~TorBrowserTeam201512
[21] https://bugs.torproject.org/17931
[22]
https://trac.torproject.org/projects/tor/query?keywords=~TorBrowserTeam201601

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
tor-reports mailing list
tor-reports@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-reports

Reply via email to