mailing list of musl libc
 help / color / mirror / code / Atom feed
* [Proposal] A simple way to make Tor-Browser-Bundle more portable and secure
@ 2016-05-09 14:15 Daniel Simon
       [not found] ` <CAPWP2JMcsTz2qh6xkYuRKj2M7=DF4cGM0DbO8GSWX930=SsqOg-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
  0 siblings, 1 reply; 5+ messages in thread
From: Daniel Simon @ 2016-05-09 14:15 UTC (permalink / raw)
  To: tor-dev-AQ2JdjIqcwS4QsDJlTKKhWD2FQJk+8+b,
	musl-ZwoEplunGu1jrUoiu81ncdBPR1lH4CV8

Hello.

How it's currently done - The Tor Browser Bundle is dynamically linked
against glibc.

Security problem - The Tor Browser Bundle has the risk of information
about the host system's library ecosystem leaking out onto the
network.

Portability problem - The Tor Browser Bundle can't be run on systems
that don't use glibc, making it unusable due to different syscalls.

Solution proposed - Static link the Tor Browser Bundle with musl
libc.[1] It is a simple and fast libc implementation that was
especially crafted for static linking. This would solve both security
and portability issues.

What is Tor developers' opinion about this? I personally don't see any
drawbacks and would be interested in discussing this further.

Sincerely,
Daniel

[1] https://www.musl-libc.org/
_______________________________________________
tor-dev mailing list
tor-dev-AQ2JdjIqcwS4QsDJlTKKhWD2FQJk+8+b@public.gmane.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2016-10-29 21:59 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-05-09 14:15 [Proposal] A simple way to make Tor-Browser-Bundle more portable and secure Daniel Simon
     [not found] ` <CAPWP2JMcsTz2qh6xkYuRKj2M7=DF4cGM0DbO8GSWX930=SsqOg-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2016-10-29 13:51   ` Daniel Simon
     [not found]     ` <CAPWP2JNevbdXZwex+oU82uDn46u38fcmcBUaj0bqwo-Ry6---A-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2016-10-29 13:54       ` Jessica Frazelle
2016-10-29 14:39   ` Tom Ritter
2016-10-29 21:59     ` Re: [tor-dev] " Szabolcs Nagy

Code repositories for project(s) associated with this public inbox

	https://git.vuxu.org/mirror/musl/

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).