Tor's Bug Smash Fund: Year Two!
The Bug Smash Fund is back for its second year. In 2019, we launched Tor’s Bug Smash Fund to find and fix bugs in our software and conduct routine maintenance. Maintenance isn’t a flashy new feature, and that makes it less interesting to many traditional funders, but it’s what keeps the reliable stuff working--and with your support, we were able to close 77 tickets as a result.
These bugs and issues ranged from maintenance on mechanisms for sending bridges via email and collecting metrics data to improving tor padding, testing, onion services, documentation, Tor Browser UX, and tooling for development. This work keeps Tor Browser, the Tor network, and the many tools that rely on Tor strong, safe, and running smoothly.
And there’s so much more we can accomplish. Nineteen tickets tagged BugSmashFund are still open, and as you know, a big part of building software is ensuring that you can address issues when you find them. As such, starting August 1, every donation we receive during the month of August will count towards the Bug Smash Fund 2020.
Learn more about the Bug Smash Fund and how to contribute.
Starting July 8th through August 10th, the Tor Project is running a campaign called #MoreOnionsPorfavor to raise awareness about onion sites, that is, websites available over onion services. We recently released a feature called Onion-Location in Tor Browser that announces to users if a website has an onion site available.
Many web administrators already joined us and made their websites available over onion services and Onion-Location. For example, ProPublica, DEF CON, Privacy International, Riseup.net, Systemli.org, Write.as.
Join us to make a more secure web! To participate, enable Onion-Location, share your onion site using the hashtag #MoreOnionsPorFavor on your favorite social media, and we'll select some onion service operators to receive a Tor swag. Find out how to launch your onion service and set up Onion-Location.
Onion Service version 2 deprecation timeline
More than 15 years ago, Onion Service (at the time named Hidden Service) saw the light of day. It was initially an experiment in order to learn more on what the Tor Network could offer. The protocol reached its version 2 soon after deployment.
Version 2 developed into a strong stable product that has been used for over a decade. Since then, onion service adoption has increased drastically, from the .onion tld being standarized by ICANN, to SSL certificates being issued to .onion addresses. Today, onion services support an ecosystem of client applications: from web browsing to file sharing and private messaging.
In 2015, a large scale development effort spanning over 3 years resulted in onion services version 3. On January 9th 2018, Tor version 0.3.2.9 was released which was the first tor supporting onion service version 3. Every single relay on the Tor network now supports version 3. It is also today'sdefault version when creating an onion service.
With onions v3 standing strong, we are at a good position to retire v2. It has completed its course and provided security and privacy to countless people around the world. But more importantly, v2 has created and propulsed a new era of private and secure communication. Prepare for v2 retirement with our planned deprecation timeline.
These releases fix TROVE-2020-001, a medium-severity denial of service vulnerability affecting all versions of Tor when compiled with the NSS encryption library. (This is not the default configuration.) Full changelog.
This is the second alpha release in the 0.4.4.x series. It fixes a few bugs in the previous release, and solves a few usability, compatibility, and portability issues. Full changelog.
This is an Android-only release. It updates Firefox to 68.10.1esr and features important security updates to Firefox. Full changelog.
This release updates Firefox to 68.10.1esr. It also includes important security updates to Firefox. Full changelog.
This release update Firefox to 68.10.0esr, Tor to 0.4.4.1-alpha, and NoScript to 11.0.32. This release also includes important security updates to Firefox. Full changelog.
What We're Reading
"Homeland Security worries COVID-19 masks are breaking facial recognition, leaked document shows," The Intercept.
"Appeals court blocks Trump appointee's takeover of web nonprofit," Politico.
"A New Map Shows the Inescapable Creep of Surveillance," WIRED.
"The Trump Administration is Attacking Critical Internet Privacy Tools," Vice.
"How to Check Your Devices for Stalkerware," WIRED.
"EFF to Court: Trump Appointee’s Removal of Open Technology Fund Leadership Is Unlawful," EFF.
Events with Tor
Join Our Community
Getting involved with Tor is easy. Run a relay to make the network faster and more decentralized. Run a bridge to help censored users access Tor.
Learn about each of our teams and start collaborating.
Donate to help keep Tor fast, strong, and secure.