tor-browser

The Tor Browser
git clone https://git.dasho.dev/tor-browser.git
Log | Files | Refs | README | LICENSE

090 Emergency Security Issue.md (3296B)


🚨 Emergency Security Issue

NOTE This is an issue template to standardise our process for responding to and fixing critical security and privacy vulnerabilities, exploits, etc.

Information

Related Issue

Affected Platforms

- [ ] Windows - [ ] macOS - [ ] Linux

Type of Issue: What are we dealing with?

Involvement: Who needs to be consulted and or involved to fix this?

- [ ] boklm : build, packaging, signing, release - [ ] clairehurst : Android, macOS - [ ] dan : Android, macOS - [ ] henry : accessibility, frontend, localisation - [ ] jwilde : windows, firefox internals - [ ] ma1 : firefox internals - [ ] pierov : updater, fonts, localisation, general - [ ] morgan : signing, release - [ ] thorin : fingerprinting

- [ ] Networking (ahf, dgoulet) - [ ] Anti-Censorship (meskio, cohosh) - [ ] UX (donuts) - [ ] TPA (anarcat, lavamind)

- [ ] Mozilla - [ ] Mullvad - [ ] Brave - [ ] Guardian Project (Orbot, Onion Browser) - [ ] Tails - [ ] Other (please list)

Urgency: When do we need to act?

Justification

<!-- Provide some paragraph here justifying the logic behind our estimated urgency -->

Side-Effects: Who will be affected by a fix for this?

Sometimes fixes have side-effects: users lose their data, roadmaps need to be adjusted, services have to be upgraded, etc. Please enumerate the known downstream consequences a fix to this issue will likely incur.

Todo:

Communications

- [ ] bella - [ ] Relevant Applications Developers - [ ] (Optional) micah - if there are considerations or asks outside the Applications Team - [ ] (Optional) Other Team Leads - if there are considerations or asks outside the Applications Team - [ ] (Optional) gazebook - if there are consequences to the organisation or partners beyond a browser update, then a communication plan may be needed - [ ] (Optional) ruihildt - if there are consequences to Mullvad and/or Mullvad Browser

Godspeed! :pray:

<!-- Do not edit beneath this line <3 -->


/cc @bella /cc @ma1 /cc @micah /cc @morgan

/confidential

/label ~"Apps::Product::TorBrowser" /label ~"Apps::Product::MullvadBrowser" /label ~"Apps::Type::Bug" /label ~"Priority::Blocker" /label ~"Emergency"