Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When downloading a wallet via hiro.so info/data to verify the download is excluded #1146

Open
314159265359879 opened this issue Jan 5, 2023 · 0 comments

Comments

@314159265359879
Copy link

314159265359879 commented Jan 5, 2023

A users asked
Why there isn't a hash or code crc256 to check if application is genuine to thwart supply chain attacks?

We do have signed releases on github. Is there something else we should do here. Or are we assuming that a user who wants to run such a check to be able to find our github repository?
I do not think adding the data to the download (a seperate file with the hashes?) would solve the issue because if hiro.so got compromised both could be replaced by the hacker providing false security.

Should we perhaps provide the option to (a) direct to Github for a user to pick the appropriate version for themselves and/or (b) provide the option to verify authenticity?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant