pull down to refresh
deleted by author
Haha yes. Like a secret key hidden in plain sight.
deleted by author
Yes
You just summarized my post with a few words haha
Wait, no. The dev signs the software (or whatever). The signature IS the hash "encrypted" with the private key.
deleted by author
deleted by author
madness 😂
so if abcd.dmg.asc with abcd.dmg - no need.
but abcdfrfsve.dmg.asc with abcd.dmg - need.
did you use a new key to sign that?
did you use a new key to sign that?
No, I just used gpg --clearsign. I just hoped it would pick the right key haha.
Due to the markdown formatting, it might get tricky, but you should be able to use go to #437477/edit to see the raw formatting.
edit: Oh no, it picked a wrong GPG secret key 🙈
Will post new message with my ekzyis@ekzyis.com GPG key
deleted by author
used wrong GPG secret key above, lol
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
I still don't get the part when you need to do the checksum or not? 👀
No worries! This means I didn't explain well enough (among other things) 👀
You need to do the checksum stuff when the name of the signature file without .asc at the end is not the same as the software you downloaded.
Examples:
- Electrum: Signature is named
electrum-4.5.3.dmg.ascand software is namedelectrum-4.5.3.dmg. This means the software was signed. - Sparrow: Signature is named
sparrow-1.8.2-manifest.txt.ascand software is namedSparrow-1.8.2-x86_64.dmg. This means that the software was not signed butSparrow-1.8.2-manifest.txt.
So it depends on what was signed. You can sign anything. Like I just signed this message. Try to verify the signature :)
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCAAwFiEER3BdefVXE2Q1VvSZ7Ow39o+3M5gFAmXaJGUSHGVrenlpc0Bl
a3p5aXMuY29tAAoJEOzsN/aPtzOYTCIP/1pMj/AJGDa3BKXDbB7Uc5lZ5agsPlTw
0p+eP9zIFUdcFNNTF5UZRi/QJn2deD/9fkSG/cBcTE0wH7cK0HRNl+fQ3balNOta
ublTjOnbEEp+2LcAoxfbjvvywjxW9QL7N9JLJ5yOfrLUpWS0w8OM6u5Z+gPBsYGG
NaJyigh7cSAx/uAgNMFKA+aidGaqG+oBGtK2xxqdj2T0kukydc2l2sl40/sotRB/
Q+4xmOrg0o+dXXAiorlgFaX8o+bPKk1O4bnDFClQW+m3/PajWEJaOGS50KD2kbmi
GweFZSooAgkzH4t5WRoTLtzdAqu5oM5idRkklNCJaXSpCYLFrgp6mTLiIOwqG6fd
JOSIZQv4h12G210fhNu3k0xr9Y4fXrYM5bH+uH3JUeUATXMIZbx4mN5iIlMLA68r
r+9yT43UgHcUFqRxg8SxCPY0CcIAm+djdfvcv3eY1I8HsxEaL/84gS+WqgPmvTZ3
LmX8Tq4lsl7lVy46efaFxP2yXU4hCriWlfuIf/7/ddgiwdKxiFHBzHzbuWcGdq9Z
x2hbFAIMj3850IpkTPLlfYypFmvniLqEEWK38Lb3518m/+Bv40gJFwAimPXgZUK6
6TJqKEchtk71J8KabB2bLCHae0AVj1mOFx3z890pU5gmoQXDEhWZ6gz8wVTzN5zY
PVfJJYgeWN/s
=oo4+
-----END PGP SIGNATURE-----
deleted by author
To be fair, I think if the instructions mention to import the key from a site like Keybase like Sparrow does, I think it's fine. Most important thing is to not import the public key from the same site you received everything else and I think if people just follow instructions, they automatically do that.
It just makes me feel uneasy if people are not aware that this is important. The why's and so on.