Double Torbrowser-update of the same version?

Hello,

I have a question regarding the updates for the Tor browser:

Yesterday, I updated the Whonix Workstation to the latest version (15.20) using the “Torbrowser-Downloader” and also updated the associated “Anon-Whonix”-VM.

I just called up a Disp-VM based on this workstation, and the green update dot appears again.

Subsequently, I reopened the Tor Browser downloader on the workstation because I thought a new version 15.21 had been released.

But that wasn’t the case. Instead, it indicated once again that it needs to be updated to 15.20.

When I finished the update, I checked “Anon-Whonix” again, but it indicated that the update is up to date (15.20).

How is it possible that there should be two updates to the same version?

I checked in the “TorControlPanel” during the update which IP addresses it was running on. The first time it showed an IP address, the second time only “TorProject.org”.

How is that to be interpreted, or how can one be sure that the correct update is actually being applied? I am aware that everything is signed and has the correct fingerprint, which I generally verify. Nevertheless, it unsettles me because “it could be that …”

What do you think about it?

I noticed something else: In the past, after the Tor Browser update was completed, a window would appear confirming that the update was installed or went well. It hasn’t appeared for some time now. Is that intentional?

Thanks for your opinions.

It’s a bit unclear what your setup is here, but the symptoms you’re describing sound like you launched Tor Browser in the whonix-workstation-18-dvm DispVM template (which is distinct from both the whonix-workstation-18 template and the DispVMs themselves). If you do this once, it may break Tor Browser updates in DispVMs from that point until you fix it. See:

(Click the “Expand” button, the last bullet point in that section describes the symptoms you’re experiencing, and why starting Tor browser in a DispVM template will cause this.)

See also:

(Note, the information in the above two links may be out-of-date; it looks like the script that sets up Tor Browser in a DispVM currently works by bind-mounting the system-wide Tor Browser installation dirs into the home dir, which should be immune to the issue described above.)

It sounds like you might have a more complicated setup where you have anon-whonix acting as both an AppVM and a DispVM template somehow. If that’s what you’re doing, don’t do that, you should keep anon-whonix and whonix-workstation-18-dvm separate.

I’m not sure what this is referring to; Tor Control Panel doesn’t display IP addresses to my awareness (unless you’re looking at IP addresses in bridge configuration or Tor logs).

I don’t remember that feature, but it’s been a while since I’ve used update-torbrowser manually, so that could be because I’ve forgotten it.

1 Like

Thank you very much for your opinion, I will explain it a bit more:

  1. I keep the dvm template and “anon-whonix” strictly separate.

  2. I simply started the Tor Browser downloader in “whonix-workstation-18” for the update.

After the update, I shut down the workstation template again. Then I launched the Tor Browser in “anon-whonix” and updated it in the update menu at the top right (green dot).

I always practice this procedure.

I am therefore very sure that I did not update the Tor browser from the dvm template.

To the Tor Control Panel: I always access it from “sys-whonix”, then go to “Utilities” and here to “Onion Circuits”. There you can then see which IP address comes from the update server, provided you don’t have any other disp-VMs that depend on sys-whonix, or other tabs open in the disp-VM window. That’s what I meant.

OK, that clarifies things. I’m still not 100% sure what you’re looking at, but I think what you’re saying is:

  • First, you opened the whonix-workstation-18 TemplateVM, and ran Tor Browser Downloader in it. That is normal and should work without issues.
  • Then, you opened the anon-whonix AppVM, opened Tor Browser, and used Tor Browser’s built-in updater to update it. That also is normal and should work fine.
  • Then, you opened a DispVM based on the whonix-workstation-18-dvm DispVM template which is itself based on the whonix-workstation-18 template. When you did this, you saw another Tor Browser update notification. This is not normal, since the DispVM is supposed to inherit the Tor Browser update from the whonix-workstation-18 template.
  • Then, you opened the anon-whonix AppVM, opened Tor Browser Downloader to see what Tor Browser version was available, and discovered that there wasn’t a newer-yet-still version of Tor Browser available.

There are a few possible explanations for this behavior if the above is what happened, in order from most likely to least likely:

  • Your whonix-workstation-18-dvm DispVM template is broken and has a Tor Browser installation in its home directory rather than in the system-wide directory the template stores it in.
  • You had the DispVM open already before doing the updates.
  • Tor released a minor update for Tor Browser that didn’t involve a major version bump.
  • Someone is exploiting a bug in Tor Browser or stolen keys to deliver your DispVM a malicious update. (This is very, very unlikely, but is included here for completeness.)

There might be other explanations too. One question I have is, if you open a new DispVM and launch Tor Browser in it, can you check what Tor Browser version is running before it starts automatically updating? That would help us figure out if your DispVM template is broken or not.

Hallo,

The first three points, as you described them, are correct, but the last one is not:

“Then, you opened the anon-whonix AppVM, opened Tor Browser Downloader to see what Tor Browser version was available, and discovered that there wasn’t a newer-yet-still version of Tor Browser available.”

I did not reopen the anon-whonix app with the downloader, but rather the downloader in the whonix-18-workstation again. There, I was not shown an even newer version (15.21, as I assumed) to which I could update, but rather that I should update to the same version again (15.20, which I had already updated to once).

Regarding the four possibilities you described about what might have happened:

Regarding option 1: This could be tested by deleting and recreating a new disp-VM template.

Regarding option 2: I am quite sure that I did not have any disp-VM open before and during the update. I avoid that for security reasons to prevent side-channel attacks.

Regarding option 3: I didn’t know that Qubes makes a difference here when the Tor project delivers either minor or major updates. The problem I described has not yet appeared with smaller updates from Tor.

Regarding possibility 4: That would indeed be a big problem. I also consider it unlikely. Nevertheless, the only clue that can be considered is that during the first update in the Tor Control Panel, an IP address appeared, and the second time only “torproject” appeared. Unfortunately, I didn’t write down the IP the first time because I didn’t expect it. I also take samples of the IP addresses with the Tor Control Panel during Qubes updates to see if anything unusual or noteworthy appears, as I have observed some inconsistencies for some time now that generally affect the Tor network itself, its acceptance by the economy and politics, and thus its overall usability.

To answer your question:

Yes, you can check this by opening the menu bar, then going to “Help” and then to “About Tor Browser.” A window will appear showing whether the Tor Browser version in the Disp (or in another VM that uses Tor) is up to date or not. If not, a green dot would briefly appear in the top right corner shortly after opening a disp-VM, indicating that an update is available.

That’s normal behavior, so that shouldn’t be a problem. Tor Browser Downloader isn’t an upgrader per se, but more of a (re)installer. In the template, it creates a fresh installation of Tor Browser in a system-wide “cache” location that can be inherited and copied into $HOME within AppVMs (or bind-mounted into $HOME in DispVMs).

I may have been unclear. I understand you see a green dot, that’s not the info I’m looking for. I’d like for you to open Tor Browser in a DispVM, click the hamburger menu in the upper-right corner of the window, click Help → About Tor Browser, then type here the version number you see in the “About Tor Browser” dialog. I’m looking for that exact version number.

Okay, I understand. The number I see in a disp-VM in “About Tor Browser”-dialog is 15.0.20. Above, I forgot the “0” between “15” and “20”.

Just to confirm, you see both 15.0.20, and a green dot, at the same time?

With reference to my description from my first post:

-–"I just called up a Disp-VM based on this workstation, and the green update dot appears again.

Subsequently, I reopened the Tor Browser downloader on the workstation because I thought a new version 15.21 had been released.

But that wasn’t the case. Instead, he indicated once again that it needs to be updated to 15.20."—

To explain this post a bit more precisely:

In the disp-VM, the green dot appeared, so I closed the disp and called the Tor Browser downloader again in whonix-18-workstation, which indicated that it should be updated to version 15.0.20.

I did it this way because the Tor Project has previously released two updates within two days, and I thought it would be the same this time, and an update with the number 15.0.21 was released. Mozilla has recently closed quite a few security vulnerabilities, and I assumed that this time it was the same. As I said, that was not the case; instead, I was supposed to update to 15.0.20 again.

I understand all of that. I’m sorry to be very particular here, but I’m digging for a specific bit of info that isn’t covered by that. The reason for that is:

  • If you can see on your screen, simultaneously, both a “15.0.20” in the “About Tor Browser” dialog, and a green update dot on the hamburger menu, that eliminates the possibility that your DispVM setup is broken.
  • If you see on your screen, simultaneously, a version number earlier than “15.0.20” in the “About Tor Browser” dialog, and a green update dot on the hamburger menu, that means your DispVM setup is almost certainly broken.
  • If you see a “15.0.20” in the “About Tor Browser” dialog, but the green dot is now gone, then the results are inconclusive.

Right now I know you see a version number of “15.0.20” pretty much everywhere a version number should show up, and I know you see a green update dot, but I don’t know if you see both at the same time in the same VM. Without that info, I can’t tell which of the scenarios mentioned above is the case.

(For what it’s worth, I just tried to reproduce this behavior and was not able to. On my end, I see “15.0.20” in the “About Tor Browser” dialog, but there is no green update dot and I’m told that Tor Browser is up-to-date.)

I believe there is a misunderstanding. At the moment, right now, everything is fine and I see the current version 15.0.20 in all disps and no (!) green dot.

I was concerned about the behaviour that the update in the workstation downloader to 15.0.20 was apparently possible twice. That’s why I opened the first post.

The first time, I updated the Tor Browser in the workstation’s downloader to 15.0.20, and then the green dot appeared again when opening a new disp-VM. I then did NOT check the version number in the disp-VM (maybe I should have), but closed the disp-VM instead, and then called the downloader in the workstation, which prompted me once again to update to 15.0.20.

I didn’t discover an earlier version number (at most, when the downloader checks if the version is up to date or not – then it showed “15.0.19” in the downloader menu window under “current version” and “15.0.20” under “new version,” which is normal).

1 Like

Hmm, strange. I guess everything is probably fine if you see 15.0.20 in the DispVM. Almost-worst case scenario, the DispVM template might be subtly broken but not horribly, or an attack occurred but was thwarted by shutting down the DispVM.

If you see this happen again in a future update, please give us an update. You might also consider deleting and recreating your whonix-workstation-18-dvm DispVM template just in case it’s broken.

Those are also my thoughts. I will closely monitor and document the next Tor Browser updates and continue this thread in case of these or similar anomalies.

Of course, something could have gone wrong in the workstation, so I’m considering reinstalling it completely.

Regarding my last paragraph from the opening post: It would be sensible if, after a successful Tor Browser update, the confirmation window appears again indicating that the update was successful.

1 Like