Bitcoin-com / Wallet

MIT License
332 stars 233 forks source link

GPG signatures required for all code commits, releases and binaries #65

Open n9jd34x04l151ho4 opened 6 years ago

n9jd34x04l151ho4 commented 6 years ago

How do outsiders know that the bitcoin.com wallet code on GitHub is legitimate?

How do outsiders know that the wallets they are downloading are really from bitcoin.com?

I am sure you must have heard about the Linux Mint hack where backdoored ISOs were placed on their servers. What exactly is stopping a hacker getting into the bitcoin.com web servers and replacing the wallet binaries with backdoored ones which send funds to an attacker's wallet whenever a transaction is sent? Web servers are notoriously insecure.

To fix this:

Required reading:

jooray commented 6 years ago

Also see: https://github.com/frankbraun/codechain http://frankbraun.org/in-code-we-trust.pdf