Skip to content

CacheCoin (CCCN) 0.1.5 for Windows

Choose a tag to compare

@triplecN triplecN released this 04 Oct 14:19
· 18 commits to main since this release

CacheCoin (CCCN) 0.1.5 for Windows

Frozen. Superseded by windows-0.2.0: statically linked executables, a pinned and verified Tor bundle, PROVENANCE.txt and Verify Download.cmd. This page is kept for the record; do not use it for new installs.

This is the sixth portable Windows package of CacheCoin: cachecoind.exe and
cachecoin-cli.exe from the tagged tree, the PowerShell launcher, the
documentation and a bundled Tor Expert Bundle.

The binaries are unsigned and this build is not reproducible. Read the whole
note before running.

Why 0.1.5 exists

0.1.4 added My Keys and Backup.cmd and Check Status.cmd. Those tools used
bin\cachecoin-cli.exe directly but did not verify the package the way the
launcher does. A tampered package (a swapped cachecoin-cli.exe, for example)
could therefore read wallet keys if the user ran the keys tool without ever
starting the launcher first. 0.1.5 closes that gap before the next audit round.

The node itself is unchanged (same patch fingerprint).

What changed in 0.1.5

  • New shared helper tools\CacheCoin-Package.ps1. Both tools now verify
    version.json fail-closed before doing anything:
    • it must exist and be readable;
    • it must list the programs, the launcher and the tools themselves;
    • every listed program, launcher or tool file must be present and match its
      sha256. A mismatch stops the tool with a clear message and tells the user
      to download the package again and check docs\VERIFY.txt.
  • docs\VERIFY.txt now documents the stronger check and its honest limit: a
    fully forged package that also replaces version.json is not caught by this
    check. The trust anchor remains the ZIP hash and the GPG signature that the
    user verifies themselves.
  • version.json now covers 35 files in this build (the helper is hashed too).

Tests on this build: backup files and sha256 output; key display behind the
typed phrase; wrong-phrase refusal; a tampered cachecoin-cli.exe is refused
with no keys shown and no node started; the restored package passes again.

0.1.4 is frozen as published; the hardening ships as 0.1.5.

Files

  • CacheCoin-Windows-0.1.5.zip
    sha256: 7c1de68e1ff44a7c0f9941c97650e28f5927f410dee96b4fde7d973ca388d23f
  • SHA256SUMS.windows.txt (sha256 of every file in the package)
  • SHA256SUMS.windows.txt.asc (detached GPG signature of the checksum file)
  • version.json (inside the package: pins, patch fingerprint, per-file sha256)

Signing key fingerprint:
7D85B6F364CC47BA9209BB54F750900C7C911728
(CacheCoin (CCCN) Releases releases@cachecoin.org; public key also in the
repository as release-key.asc and in doc/release.md).

Provenance

  • Base pins: Bitcoin Core v31.1, commit
    9be056a8a72b624dae9623b2f7bded92c2a21c91; RandomX commit
    7607fb2faed24d5a679e139a9828d194bbc644a4.
  • Patch fingerprint: 6a89aa144620ea2c019f2678ea80ae8b2de45544bc64d871cd3bb2fefcf1ddda
    (cat patches/*.patch | sha256sum). Compare it with doc/verification.md.
  • The release tag windows-0.1.5 is a signed Git tag; verify it with
    git tag -v windows-0.1.5 after importing release-key.asc.
  • Tor Expert Bundle 15.0.24 (tor 0.4.9.13); its files are hashed in
    version.json. The bundle's sha256 was checked against the Tor Project's
    published sha256sums-signed-build.txt.

Verify before running

Get-FileHash CacheCoin-Windows-0.1.5.zip -Algorithm SHA256

Unpack it, then:

gpg --import release-key.asc          # from the repository or the release page
gpg --verify SHA256SUMS.windows.txt.asc SHA256SUMS.windows.txt
sha256sum -c SHA256SUMS.windows.txt

The gpg --verify output must name the fingerprint above. The sha256 values
prove the files arrived unchanged; the signature proves the checksum file came
from that key. Neither proves the binaries can be rebuilt from source.

What this is

A portable Windows package. The node is Tor-only; the launcher starts a bundled
Tor if none is running. Data lives in %APPDATA%\CacheCoin, not ~/.cachecoin.
Double-click Start Node.cmd to begin. New users should read
docs\BEGINNER_GUIDE.md. There is no GUI and no daemon mode.

Honest limits

  • Not reproducible. The sha256 values prove only that the files arrived
    unchanged in transit; the GPG signature proves the checksum file came from
    the CacheCoin release key. Nobody can yet rebuild the exact bytes.
  • The executables are unsigned at the OS level (no Authenticode).
  • SmartScreen. Windows will show "Windows protected your PC" on first launch;
    choose More info, then Run anyway, after checking the sha256.
  • Outside the suites. The Windows .exe files are not covered by the
    repository's automated test suites. CI starts the node in regtest, verifies
    the genesis and mines one block; on this package the node was also run against
    mainnet, synced to the live tip and connected to a peer over Tor. The entry
    points and tools were exercised on a clean sandbox, including a tampered
    cachecoin-cli.exe being refused.
  • Integrity check scope. The tools' fail-closed check covers a swapped file
    inside a genuine package. It cannot cover a fully forged package that also
    replaces version.json; only the ZIP hash and the GPG signature catch that.
  • No daemon mode. cachecoind -daemon does not exist on Windows (MinGW has
    no fork()); run it in a window or under Task Scheduler.
  • Mining is a lottery. Expect weeks without a block; it may never pay. The
    PER ticket system shares fees only when fees exist. Mining costs electricity
    whether or not it pays.
  • No financial advice. This is open-source software provided as is under the
    MIT license; nothing here is financial advice, an offer or a promise of return.