Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
Trac
Trac
  • Project overview
    • Project overview
    • Details
    • Activity
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Operations
    • Operations
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value Stream
  • Wiki
    • Wiki
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Create a new issue
  • Issue Boards

GitLab is used only for code review, issue tracking and project management. Canonical locations for source code are still https://gitweb.torproject.org/ https://git.torproject.org/ and git-rw.torproject.org.

  • Legacy
  • TracTrac
  • Issues
  • #7605

Closed
Open
Opened Dec 01, 2012 by proper@proper

get the deb.torproject.org-keyring package into Debian

For first time torproject.org visitors with no knowledge about gpg and/or no trust path to The Tor Project it's difficult to verify the Tor package signing key.

The advice to download the Tor package signing key from the keyservers with a fingerprint posted from torproject.org is flawed. The first time visitor of torproject.org is already victim of a mitm this won't help. It would only help if the first time visitor won't get mitm'd at his first visit. Only further downloads would be protected.

For this reason it's not best to distribiute the Tor signing key / fingerprint through torproject.org.

Suggestion:

  1. Get the deb.torproject.org-keyring into Debian. If you can get it into the Debian keyring - even better.

  2. After 1. is done get Tor package signing key shipped by default with Debian.

This would eliminate and ease at least one step from the complicated (from user perspective) steps of gpg verification.

Getting it into Debian is strategic. Many derivatives based on Debian such as Ubuntu will include it as well.

To upload designs, you'll need to enable LFS and have admin enable hashed storage. More information
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: legacy/trac#7605