Bug Smash Fund, Year 2: Progress So Far!

Continuous integration tooling
- Fix issue when using FALLTHROUGH with ALL_BUGS_ARE_FATAL #40241
- Travis chutney tests are borked by two bad commits #40204
- Nightly Windows build failures on both 32-bit and 64-bit #40199
- Parallelize several tests to make hardened-build CI faster. #40098
- Remove AppVeyor VS2015 build #40091
- Assertion buf->tail failed in buf_assert_ok at src/lib/buf/buffers.c:919 #40076
- Use stale bot to close old pull requests #33629
- factor out supporting shell scripts from CI configs #32943
- Remove 0.2.9 from the jenkins builders #32776
- Remove Jenkins tor master jobs which don't have OpenSSL 1.1.1 #32773
- update .gitlab-ci.yml to remove broken cruft and add a complete test suite #32193
- Wrap our Travis commands with travis_retry, to mitigate network timeouts #31921
- Add a beta RUST_VERSION build to Travis CI #31862
- Should we CI-build with --disable-module-dirauth and -O0? #31560
- Run clang's scan-build in Tor's CI #30225
- update travis CI to ubuntu xenial image when available #27859
- Debian Hardened CI failures due to lack of ptrace #40275
- Run sandbox tests on Xenial and Bionic #32817
- Make the seccomp sandbox work with Ubuntu Xenial and Bionic #32722
- Define ExecuteBash in the Appveyor error block #31884
Tor Browser
- Include bridge configuration into about:preferences - tpo/applications/tor-browser #31286
- Disable tracking protection UI in FF67-esr - tpo/applications/tor-browser #26345
- AV1 playback doesn't work on Windows #40321
- Firefox icon is shown for Tor Browser on Windows 10 start menu #22654
- Prep 10.5a10 (Windows) #40227
GetTor
Network Health
Tor Network Status
Many thanks to everyone at…
Many thanks to everyone at Tor Project who help do the essential work of catching and fixing bugs, network issues, etc!
All the most powerful entities in the world hate everything which truly empowers ordinary citizens to exert some control over their own data destiny. Consequently, right from the beginning, Tor Project has been continually buffetted by an unending sequences of technical, legal and political threats. And the Great Lockdown which began early in 2020 seems to have been unusually challenging for TP and all small nonprofits. But I am cautiously optimistic that 2021 will see things improve for our side.
I hope all readers of the blog will join me in contributing whenever and to what extent we are able. Let's make Tor a user-supported NGO beholden to no government or megacorporate agenda!
P.S. A new site from ACLU-WA is at coveillance.org. Check out the Acyclica devices and the NSA secret room featured in the walking tour! Uhm.... Shouldn;t TP belong to their tech coalition?
Thanks for the note about…
Thanks for the note about https://coveillance.org/, I'll check it out.
Isn't Tor directly funded by…
Isn't Tor directly funded by the NSA? Wikipedia says so. Its weird how the NSA can't break Tor and yet they are willing to fund its development.
Tor is not funded by the NSA…
Tor is not funded by the NSA. That's FUD.
Our financials are open. You can look at an easy to read list of our funders here: https://www.torproject.org/about/sponsors/
Or dig deeper in our tax documents here: https://www.torproject.org/about/financials
And read posts that explain these documents here: https://blog.torproject.org/category/tags/form-990
Where does it say that on…
Where does it say that on Wikipedia? I can't find it.
Exactly. [citation needed]
Exactly. [citation needed]
or someone reverts your revision. Always check the History tab and Talk tab when in doubt.
Why are gitlab and…
Why are gitlab and anonticket logins subdomains of the domain, `onionize.space`, rather than torproject.org? Who owns and operates `onionize.space`? Why is it a potential MITM? Is there more Tor Project infrastructure on non-TorProject domains than those two login subdomains?
It's my domain that I use…
It's my domain that I use for highly experimental things I do related to Tor. This site will eventually be moved over to Tor Project infrastructure, but since we are working in a time constrained environment, where the internship ends soon, we wanted to get something setup as quickly as possible so that we could gather feedback from the user community.
The goal for this is to have it moved to torproject.org infrastructure and have an onion service. This is likely to happen in the near'ish future.
I like the new status page,…
I like the new status page, but I do wish the description for "directory authorities" was a tad more informative than "whatever it is that those things do". Made me laugh though!
Anyway, amazing progress. Thank you, Tor Project!
Some info that could be…
Some info that could be added there as links to improve it:
https://support.torproject.org/glossary/directory-authority/
https://gitlab.torproject.org/legacy/trac/-/wikis/doc/directory_authori…
https://consensus-health.torproject.org/
And this is interesting for its in-depth explanations:
https://matt.traudt.xyz/posts/Debunking:_OSINT_Analysis_of_the_TOR_Foun…
status.torproject.org is…
status.torproject.org is cool, much easier to understand than consensus-health.torproject.org