torproject / torbrowser-launcher

Securely and easily download, verify, install, and launch Tor Browser in Linux. This repository is a mirror of https://gitlab.torproject.org/tpo/applications/torbrowser-launcher
MIT License
777 stars 179 forks source link

SIGNATURE VERIFICATION FAILED! #726

Open StevenJohnRoberts opened 7 months ago

StevenJohnRoberts commented 7 months ago

When launching Tor, the launcher downloads the browser and then fails with the following message:

SIGNATURE VERIFICATION FAILED! Error Code: E53D989A9E2D47BF: Bad signature

Screenshot at 2024-01-20 10-02-24

I have installed the Tor-Launcher from flatpak.

I'm running on Ubuntu Mate Release 23.10, Linux Kernel 6.5.0.14-generic x86_64, MATE 1.26.2

Any help would be appreciated.

AsciiWolf commented 7 months ago

This should be reported here. The issue will hopefully be fixed in the Ubuntu 24.04 package when it gets updated to 0.3.7.

edit: Sorry, I did not notice that this ticket is about the Flatpak version.

teward commented 7 months ago

@AsciiWolf The flatpak version of the launcher isnt supported by the Ubuntu team or its developers (note you emailed me about this issue). Whoever made the flatpak needs to update it. The GPG issue was already resolved in the Ubuntu repositoires version of Tor Browser Launcher before Tor Browser changed all their localization URLs.

AsciiWolf commented 7 months ago

@teward Oops, sorry Thomas, I did not notice that the Flatpak version was mentioned! I thought that this ticket was about the deb version. Anyway, I maintain the Flatpak version and there is no issue with the GPG key.

teward commented 7 months ago

@StevenJohnRoberts can you verify which version of the flatpak you are using, and whether you are on the latest version of it or not?

goliardus commented 7 months ago

Have the issue with .deb versions on both Kali and Parrot (both 0.3.6-2). Kali just pulled from their repos and the launcher came preinstalled in Parrot. The flatpak version (0.3.7) I have in my host system has no issues (ZorinOS based on Ubuntu22.04), but now trying to install the deb throws a 404 (0.3.3).

teward commented 7 months ago

For those claiming .deb files work state OS and package version.

Many variants do not update against Ubuntu updates pocket and may have broken DEBs.

Note the 404 issue is known in Ubuntu-land but is not fixed yet. AND is different than the bad signature issue reported here.

StevenJohnRoberts commented 7 months ago

@StevenJohnRoberts can you verify which version of the flatpak you are using, and whether you are on the latest version of it or not?

As Tor won't install I can't query the version. If I look at flatpak's history, it just list the torbrowser-launcher branch as stable. flatpak itself is version 1.14.4