Open ghost opened 3 years ago
Correct me if I'm mistaken. I could not find any signed releases (Linux).
Could you please sign your releases with a gpg key (And publish your public key)? gpg
Alternatively (the cooler way of doing much security) you could release the sha256sums of the releases files and then sign these.
Is there a particular reason for you not signing your releases?
I would love to buy much DOGE and get rich, but this security issue bothers me...
did you notice the last code change were in 2016
@patricklodder @rnicoll @michilumin Could you please address this issue?
Correct me if I'm mistaken. I could not find any signed releases (Linux).
Could you please sign your releases with a gpg key (And publish your public key)? gpg
Alternatively (the cooler way of doing much security) you could release the sha256sums of the releases files and then sign these.
Is there a particular reason for you not signing your releases?
I would love to buy much DOGE and get rich, but this security issue bothers me...