|
|
= Project Chronos =
|
|
|
**Chronos** is the ancient Greek primordial deity of time.
|
|
|
Part of Part of [Project Pantheon](./org/sponsors/Pantheon), running from October 2013 until October 2014.
|
|
|
|
|
|
## Overview
|
|
|
Project Chronos is work to build a secure updater for Torbrowser, based on the Firefox updater, but incorporating the threat model and mitigations from Thandy.
|
|
|
|
|
|
This project is primarily going to be developed by Mark and Kathy of Pearl Crascent.
|
|
|
|
|
|
## [[milestone:Chronos: phase one|Phase One]]
|
|
|
### Outline
|
|
|
* opt-in
|
|
|
* minimally-changed from Mozilla's Firefox updater
|
|
|
* probably doesn't bundle HTTPS-everywhere
|
|
|
* non-Gitian MARs
|
|
|
* functional version-number management
|
|
|
|
|
|
### Tickets
|
|
|
[[TicketQuery(milestone=Chronos: phase one)]]
|
|
|
|
|
|
|
|
|
## [[milestone:Chronos: phase two|Phase Two]]
|
|
|
### Outline
|
|
|
Including some combination of the following:
|
|
|
* update over Tor, and then eventually a hidden service
|
|
|
* better signing system for updates
|
|
|
* consensus check for Torbrowser packages
|
|
|
* we update HTTPS-everywhere
|
|
|
* reproducible MAR files
|
|
|
* additional protections from the Thandy design
|
|
|
|
|
|
### Tickets
|
|
|
[[TicketQuery(milestone=Chronos: phase two)]]
|
|
|
|
|
|
## Notes
|
|
|
We're going to need hosting/CDN infrastructure to make this work. |
|
|
\ No newline at end of file |