Zeronet: Please sign releases

Created on 19 Aug 2016  路  7Comments  路  Source: HelloZeroNet/ZeroNet

It would be highly desirable if the .zip and .tar.gz files found on the Releases page were signed using GPG/PGP so that people can verify that the blobs haven't been tampered with.

Even signed commits could be useful.

As a minimum, please sha256sum the release files.

Cheers.

Most helpful comment

The signatures should also be checked by the integrated updater.

All 7 comments

The signatures should also be checked by the integrated updater.

+1
This will prevent the use corrupt downloads from man-in-middle attacks.

@HelloZeroNet This is an important issue for security and file integrity.

See here for how-to and complete details:
https://wiki.debian.org/Creating%20signed%20GitHub%20releases

Thank you.

Since last week it possible to download and update the source code via the ZeroNet network, which verifies the data integrity by checking the signiture, but I will look at pgp signing releases

FIRST SIGNED COMMIT!

Commits are now signed, :D

Closing this issue ?

Was this page helpful?
0 / 5 - 0 ratings

Related issues

blurHY picture blurHY  路  3Comments

wigy-opensource-developer picture wigy-opensource-developer  路  4Comments

sermont picture sermont  路  3Comments

DaniellMesquita picture DaniellMesquita  路  3Comments

trenta3 picture trenta3  路  3Comments