Skip to content

Add Tor Browser signing key reference to GetTor Telegram bot replies

The GetTor Telegram bot (@gettorbot) sends Tor Browser binaries and the .asc signatures, but it does not include the Tor Browser developers' signing key (torbrowser@torproject.org). As a result, users receive the .asc file without clear guidance on how to verify it.

As GetTor is used by users in censored regions, it would make sense to provide the key from the keyserver: https://keys.openpgp.org/search?q=torbrowser%40torproject.org (https://keys.openpgp.org/vks/v1/by-fingerprint/EF6E286DDA85EA2A4BA7DE684E2C6E8793298290), although I believe it's currently blocked in Russia.

Proposal

Update the bot's response to include:

  • A direct link to the Tor Browser signing key on a trusted keyserver.
  • The fingerprint so users can manually validate the key.
  • One sentence explaining that the .asc file is a signature used to verify the download.
Success!
Here's your Tor Browser ($platform).

(Advanced) If you want to verify the download, import the Tor Browser signing key and check the signature file (.asc).

Tor Browser signing key (torbrowser@torproject.org):
- Fingerprint: EF6E 286D DA85 EA2A 4BA7 DE68 4E2C 6E87 9329 8290
- Keyserver link: https://keys.openpgp.org/vks/v1/by-fingerprint/EF6E286DDA85EA2A4BA7DE684E2C6E8793298290