counter downgrade / stale mirror attacks on RecommendedTBBVersions - sign / verify tbb versions file
Securely downloading https://www.torproject.org/projects/torbrowser/RecommendedTBBVersions solely relies on SSL, is currently neither signed, nor gets verified by Tor Button.
This is problematic, because should torproject.org's web server or CA be compromised one day, applications such as Tor Button and torbrowser-launcher could be fooled into using an outdated and/or malicious RecommendedTBBVersions file.
Suggestion: could you please,
- provide a signed version of RecommendedTBBVersions,
- verify RecommendedTBBVersions in Tor Button.
To prevent downgrade and stale mirror attacks, the signature would have to be renewed after every X weeks, and rejected by the verification mechanism [+ user notification] if is is too old. (Similar to Valid-Until / #9810 (moved).)