<feed xmlns='http://www.w3.org/2005/Atom'>
<title>bitmask-vpn.git/branding/scripts, branch upstream_obfs4</title>
<subtitle>[bitmask-vpn] 
</subtitle>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/'/>
<entry>
<title>[bug] avoid installing in custom paths</title>
<updated>2021-12-15T19:02:12+00:00</updated>
<author>
<name>kali</name>
<email>kali@win</email>
</author>
<published>2021-12-15T18:45:11+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=e694a038c7edc146b63557425b307833b11aea57'/>
<id>e694a038c7edc146b63557425b307833b11aea57</id>
<content type='text'>
A vulnerability in QtIFW produces improper ACLs to be set when
installing in custom locations. This can lead to privilege escalation if
a non-privileged user overwrites the openvpn binary. Thanks to
researchers at Tenable for finding and reporting this!

Impact is considered low-medium, since an installation outside of the
suggested path is needed to trigger the issue.

Privileged execution of openvpn should be abandoned in next release, in
favor of the interactive service.

A bug upstream should be filed since other projects could be affected by
this vulnerability too.

-Resolves: #569
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
A vulnerability in QtIFW produces improper ACLs to be set when
installing in custom locations. This can lead to privilege escalation if
a non-privileged user overwrites the openvpn binary. Thanks to
researchers at Tenable for finding and reporting this!

Impact is considered low-medium, since an installation outside of the
suggested path is needed to trigger the issue.

Privileged execution of openvpn should be abandoned in next release, in
favor of the interactive service.

A bug upstream should be filed since other projects could be affected by
this vulnerability too.

-Resolves: #569
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] fix makefile, installer</title>
<updated>2021-11-30T12:54:01+00:00</updated>
<author>
<name>kali</name>
<email>kali@leap.se</email>
</author>
<published>2021-11-30T12:51:46+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=451f6fef9d707e121cd3d14b3114f7be4e3b2444'/>
<id>451f6fef9d707e121cd3d14b3114f7be4e3b2444</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] allow multi-provider</title>
<updated>2021-11-23T20:51:28+00:00</updated>
<author>
<name>kali kaneko (leap communications)</name>
<email>kali@leap.se</email>
</author>
<published>2021-11-23T19:43:12+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=28876566144cc74a32eb45f2fa4d966ebef8b0b2'/>
<id>28876566144cc74a32eb45f2fa4d966ebef8b0b2</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] fix typos</title>
<updated>2021-07-15T16:21:53+00:00</updated>
<author>
<name>kali</name>
<email>kali@leap.se</email>
</author>
<published>2021-07-15T16:20:18+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=ae096096e34de7e84047a29e487103f7ce6c391a'/>
<id>ae096096e34de7e84047a29e487103f7ce6c391a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] improve stapler script</title>
<updated>2021-07-15T15:23:55+00:00</updated>
<author>
<name>kali</name>
<email>kali@leap.se</email>
</author>
<published>2021-07-15T15:10:31+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=8fd0fcc5eaa9b5fc7692304cdf24560dfb8862ab'/>
<id>8fd0fcc5eaa9b5fc7692304cdf24560dfb8862ab</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] add stub for stapler script</title>
<updated>2021-07-14T19:31:21+00:00</updated>
<author>
<name>kali kaneko (leap communications)</name>
<email>kali@leap.se</email>
</author>
<published>2021-07-14T19:31:21+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=d9131ae8c78519e6c8e17285ae29caa06e704892'/>
<id>d9131ae8c78519e6c8e17285ae29caa06e704892</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] document how to test builds for float</title>
<updated>2021-07-07T17:41:24+00:00</updated>
<author>
<name>kali kaneko (leap communications)</name>
<email>kali@leap.se</email>
</author>
<published>2021-07-07T17:40:01+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=39eb4a176ef2fe52247db4ca551fc0f945ffa2ae'/>
<id>39eb4a176ef2fe52247db4ca551fc0f945ffa2ae</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] abort install if we running an old version</title>
<updated>2021-03-05T11:16:25+00:00</updated>
<author>
<name>kali</name>
<email>kali@win</email>
</author>
<published>2021-03-03T21:59:03+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=7ed49b92ff19205af276dee371174579c8b4c811'/>
<id>7ed49b92ff19205af276dee371174579c8b4c811</id>
<content type='text'>
stop if:

- bitmask is running (we don't want to mess with the helper if the app
  is running)
- we cannot stop the service for some reason.

powershell gives more flexibility to stop services, but Remove-Service
is not present in PS &lt; 6, so we try to remove the service from the
post-install too (the golang helper will complain about an eventlog
registry key).

this could probably be improved in the helper, but we'll be moving to
the official openvpnserv2 service for 0.21.4. we might want to revisit
the current helper for the firewall/killswitch.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
stop if:

- bitmask is running (we don't want to mess with the helper if the app
  is running)
- we cannot stop the service for some reason.

powershell gives more flexibility to stop services, but Remove-Service
is not present in PS &lt; 6, so we try to remove the service from the
post-install too (the golang helper will complain about an eventlog
registry key).

this could probably be improved in the helper, but we'll be moving to
the official openvpnserv2 service for 0.21.4. we might want to revisit
the current helper for the firewall/killswitch.
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] improve osx installer</title>
<updated>2021-02-26T21:40:44+00:00</updated>
<author>
<name>kali</name>
<email>kali@leap.se</email>
</author>
<published>2021-02-19T11:20:55+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=4a4b6b46f84c28640c711655f4f3c339ccf8fbba'/>
<id>4a4b6b46f84c28640c711655f4f3c339ccf8fbba</id>
<content type='text'>
- install into global /Applications
- document how to troubleshoot helper
- uninstall app is visible on top-level folder
- improve detection of running processes for old and new binaries

- Closes: #441
- Closes: #445
- Closes: #435
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
- install into global /Applications
- document how to troubleshoot helper
- uninstall app is visible on top-level folder
- improve detection of running processes for old and new binaries

- Closes: #441
- Closes: #445
- Closes: #435
</pre>
</div>
</content>
</entry>
<entry>
<title>[pkg] customize windows installer</title>
<updated>2020-11-05T23:38:40+00:00</updated>
<author>
<name>kali</name>
<email>kali@win</email>
</author>
<published>2020-11-05T23:36:30+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/bitmask-vpn.git/commit/?id=ea0f55bc6c92402ecbbc2af14c3e1074988cb413'/>
<id>ea0f55bc6c92402ecbbc2af14c3e1074988cb413</id>
<content type='text'>
I kind of liked the "classic" style more (looks cleaner), but it looks
like we only can customize the logo etc with the "modern" look and feel
in windows.

I think the way to go would be to add a QStyleSheet to the installer
(and adding logo etc there), but I think that is going to take some
reading. this is not too bad for now, at least we can put logos to
differentiate riseup/calyx etc.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
I kind of liked the "classic" style more (looks cleaner), but it looks
like we only can customize the logo etc with the "modern" look and feel
in windows.

I think the way to go would be to add a QStyleSheet to the installer
(and adding logo etc there), but I think that is going to take some
reading. this is not too bad for now, at least we can put logos to
differentiate riseup/calyx etc.
</pre>
</div>
</content>
</entry>
</feed>
