Package Details: tor-browser-bin 14.0.1-1

Git Clone URL: https://aur.archlinux.org/tor-browser-bin.git (read-only, click to copy)
Package Base: tor-browser-bin
Description: Tor Browser Bundle: anonymous browsing using Firefox and Tor
Upstream URL: https://www.torproject.org/projects/torbrowser.html
Licenses: MPL-2.0
Conflicts: tor-browser
Provides: tor-browser
Submitter: FabioLolix
Maintainer: grufo (jugs)
Last Packager: grufo
Votes: 1282
Popularity: 2.99
First Submitted: 2023-09-24 17:45 (UTC)
Last Updated: 2024-10-30 11:09 (UTC)

Pinned Comments

grufo commented on 2019-08-15 02:22 (UTC)

Before running makepkg, you must do this (as normal user):

$ gpg --auto-key-locate nodefault,wkd --locate-keys torbrowser@torproject.org

If you want to update tor-browser from AUR without AUR helpers you can run in a terminal:

$ tor-browser -u

Latest Comments

« First ‹ Previous 1 2 3 4 5 6 7 .. 77 Next › Last »

solarisfire commented on 2024-09-06 04:51 (UTC)

This is failing today:

==> Verifying source file signatures with gpg...
    tor-browser-linux-x86_64-13.5.3.tar.xz ... FAILED (unknown public key 157432CF78A65729)
==> ERROR: One or more PGP signatures could not be verified!
 -> error making: tor-browser-bin-exit status 1
 -> Failed to install the following packages. Manual intervention is required:
tor-browser-bin - exit status 1

BlackDex commented on 2024-09-05 07:06 (UTC)

@Powerless read the PKGBUILD file and check the source of the binaries. https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=tor-browser-bin

There you see those files are downloaded from the torproject site it self. The maintainer does not build these files, they just update where and when needed.

Powerless commented on 2024-08-18 00:36 (UTC)

Honest question: How do I know that this package is secure and has not been infected by the maintainer?

tomilov commented on 2024-07-16 17:14 (UTC)

Problem with sha256 is still present (on 3h fresh arch):

==> ERROR: sha256sums does not allow empty values.
==> ERROR: sha256sums does not allow empty values.
 -> error downloading sources: /home/anatoliy/.cache/yay/tor-browser-bin 
         context: exit status 12 


:: (1/1) Parsing SRCINFO: tor-browser-bin
pub   rsa4096 2014-12-15 [C] [expires: 2025-07-21]
      EF6E286DDA85EA2A4BA7DE684E2C6E8793298290
uid           [ unknown] Tor Browser Developers (signing key) <torbrowser@torproject.org>
sub   rsa4096 2021-09-17 [S] [expires: 2024-08-23]

==> ERROR: sha256sums does not allow empty values.
==> ERROR: sha256sums does not allow empty values.
 -> error making: tor-browser-bin-exit status 12
 -> Failed to install the following packages. Manual intervention is required:
tor-browser-bin - exit status 12

rafaelff commented on 2024-07-15 17:39 (UTC)

Maintainer, please consider checking the _urlbase variable's browsing output for 404 HTTP error, otherwise an error in _dist_checksum() function will cause a confusing empty sha256sums array.

Example of verification you could do before _dist_checksum():

curl --silent --fail "$_urlbase" > /dev/null
if [ $? == 22 ]; then
  echo "Page '$_urlbase' not found, PKGBUILD possibly need pkgver bump. Please flag out of date in AUR page."
fi

p.s. 22 exit code means HTTP page not retrieved, as per curl man page.

DWestCoast commented on 2024-07-13 10:34 (UTC) (edited on 2024-07-13 10:35 (UTC) by DWestCoast)

To solve sha256sum errors change pkgver to 13.5.1

veox commented on 2024-05-14 17:54 (UTC)

makepkg fails for me with:

==> ERROR: sha256sums does not allow empty values.
==> ERROR: sha256sums does not allow empty values.

Cody_Learner commented on 2024-03-18 18:23 (UTC) (edited on 2024-03-18 18:23 (UTC) by Cody_Learner)

Regarding the required key, you can also manually call the keyserver where this key resides(*). ie:

 gpg --keyserver keys.openpgp.org --recv-key EF6E286DDA85EA2A4BA7DE684E2C6E8793298290 

(*) https://support.torproject.org/tbb/how-to-verify-signature/

Tor Browser Developers key is also available on keys.openpgp.org ....

HunabKu commented on 2024-02-29 07:50 (UTC) (edited on 2024-02-29 07:51 (UTC) by HunabKu)

you can also use this to get the key :

curl -s https://openpgpkey.torproject.org/.well-known/openpgpkey/torproject.org/hu/kounek7zrdx745qydx6p59t9mqjpuhdf |gpg --import -

Official Source : https://support.torproject.org/tbb/how-to-verify-signature/