Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upverification-issue: .sig-file corrupt for Sia-UI #753
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
lukechampine
Dec 29, 2017
Member
Signature verification was documented in the first release that we signed: https://github.com/NebulousLabs/Sia-UI/releases/tag/v1.0.3
I agree that this could be exposed more visibly, though. I'm sure you are not the first person to try to verify the key with gpg and be concerned when it failed. Perhaps we should add a section with the openssl verification command to the README.
I'm also open to switching to gpg. IIRC we're not locked in to openssl for any technical reason.
|
Signature verification was documented in the first release that we signed: https://github.com/NebulousLabs/Sia-UI/releases/tag/v1.0.3 I agree that this could be exposed more visibly, though. I'm sure you are not the first person to try to verify the key with |
johays commentedDec 26, 2017
I recently downloaded the Sia-UI from Github. I also downloaded the corresponding .sig-file.
Anyhow, I get an GPG-error when I try to verify:
I've tried from different machines with different downloads from four different locations. Still, I get the same error.
I find it strange that software like this that deals with peoples money doesn't take signature-verification super seriously? There are some outstanding resources on how to do proper verification, like here and here. Why is there no proper documentation concerning verification of the software neither on Github or sia.tech? From a security-perspective I find this very troubling.