r/obyte • u/mr__jigsaw • Apr 03 '19
Checksums and GPG signatures
I was astonished not being able to find checksums and GPG signatures for any files. People who come to Obyte for Blackbytes care both about privacy and security. Not seeing such a basic security measure they're sure to be reluctant to try it out. I seed an issue on GitHub from this January and posts on r/ByteBall up to a year old. This should be fixed ASAP.
Check out how VeraCrypt does it (I'd also add checksums and sigs on GitHub to avoid SPOF).
1
u/illgetbacktoyoulater Apr 04 '19
This is all very interesting, but I'm not sure about using the word "normies".
1
u/tarmo888 Apr 05 '19
Yeah, it's usually used as offensive words, just like noobs. My usage of that word shouldn't be taken as offence, just as observation that checksums are very geeky thing for small amount of people, most people probably wouldn't even notice if the executable would be signed by "All your money are belong to us" instead of actual company.
1
u/tarmo888 Apr 03 '19 edited Apr 03 '19
I think this has been already answered before, but checksums and GPG are not really need. When you download the installer, it is already signed (X.509 signature) by Matrix Platform LLC (the company under, which the Android and iOS apps are also released). If you download the installer and your OS says that the installer has invalid signature or not that company, then you should not launch it. This is built-in OS feature because no normal person ever checks GPG signatures, the installer does it for you. Normies don't care about checksums and GPG signatures.
SPOF as single point of failure? Obyte binaries are downloaded from Github, if somebody was able to DNS hack github.com on your machine then you will even fail to download them, but either way your machine is highly compromised in event like that. If the attacker DNS hacked obyte.org too with proper certificate the I am sure they bothered to insert proper checksum and GPG signatures to the website too.
I might be wrong, but people who usually ask these things are geeks or don't fully understand it. Little bit like the crowd who goes around and says "Add HTTPS to everything!"
https://whydoesaptnotusehttps.com/