JellyBookOrg / JellyBook

A nice way to read books and comics from Jellyfin
MIT License
443 stars 12 forks source link

signing key issues #190

Open Kara-Zor-El opened 1 week ago

Kara-Zor-El commented 1 week ago

Hey @IzzySoft, I wasn't sure the best way to contact you. Currently my Mac isn't turning on and I don't think I saved a copy of the private keys anywhere else. There is a chance I may have to change the signing key once more. If there's anything I can do to prove my identity or anything, let me know, so sorry 🥲.

Kara

IzzySoft commented 1 week ago

I wasn't sure the best way to contact you.

Totally fine this way, thanks!

There is a chance I may have to change the signing key once more

Details are outlined in How to keep your key safe and what measures to take for the event of loss? Quick check:

That makes verification pretty hard. Apart from which, everyone using your app will have to uninstall and reinstall whenever the key changes…

I'm out of ideas how we can perform the verification – but maybe reading the linked article gives you an idea?

Kara-Zor-El commented 1 week ago

Hi,

I can use my original key (I still have that on my previous computer). I can start signing commits now. In order to contact me, please refer to here: Contact Me. Additionally, there's a few people who can vouch for me. jmshrv, sevenrats, and jdk-21 are part of the Tentacle API used here who all have alternative ways of contacting me as well (not @'ing them that way not to disturb me). Additionally, Chaphasilor who works on Finamp has committed to this repo.

Thanks, Kara

IzzySoft commented 2 days ago

Apologies for the delay, Kara – I didn't forget you, just was drowning in other tasks (actually, still am).

Well, verifying this now seems to be a tricky thing. Yes, definitely start signing commits now, it's never "too early" for that. For the other details, let me play the "devil's advocate" for a moment:

Assuming someone managed to take over your Github account:

So you see, things can get tricky if one wants to make "absolutely sure" and have some proof to show. So it's good to take precautions as early as possible. But we'll get this sorted.

IzzySoft commented 2 days ago

OK, thanks Kara! We've successfully verified on a different channel now. Just go ahead then as discussed, and we'll switch to another key if needed.