Nick Mathewson:
With proposal 227 in 0.2.6.3-alpha, we added a way for authorities to vote on e.g. the latest versions of the torbrowser package.
It appears we aren't actually using that, though. Are we planning to use it in the future?
It might be a candidate for update hardening, e.g. in the Tor Browser case. Note, though, that there are a bunch of issues with the Tor Browser side of the proposal (https://trac.torproject.org/projects/tor/ticket/14676#comment:1). We'd need to solve those first before starting any implementation. I guess this could be a nice item for a funding proposal if we think that's the way to do the update hardening.
Georg