oxen-io / session-website

Session Website | Send Messages, Not Metadata.
https://getsession.org
GNU General Public License v3.0
14 stars 9 forks source link

Document PGP release signature usage on getsession.org/download #36

Open maltfield opened 5 months ago

maltfield commented 5 months ago

Is there an existing request for feature?

What feature would you like?

Document how to cryptographically verify downloads on the getsession.org download page

Expected behaviour

When I go to download the Session desktop client, I should also see instructions on how to verify the authenticity of the file after download and before install. Or, at least, a link to the document that describes this.

Actual behaviour

I see no mention about cryptographic authenticity verification on the download page

Steps to reproduce

  1. Go to https://getsession.org/download
  2. Click "Linux" (or whatever platform I'm on)
  3. See the AppImage is downloading
  4. Look around on page for the word "verify" or "PGP" or "GPG" or "signature"
  5. ???
  6. Get confused and open ticket

Anything else?

No response

maltfield commented 5 months ago

Note: This is not a support request asking for information on how to verify release signatures.

The only resolution to this ticket is by updating the getsession.org download page with the information (or a link-to the information) that documents how users can verify release signatures.

maltfield commented 5 months ago

Here are some examples of "verifying this release" project documentation from other projects

  1. https://www.apache.org/info/verification.html#CheckingSignatures
  2. https://docs.featherwallet.org/guides/linux#verifying-the-download-optional
  3. https://support.torproject.org/tbb/how-to-verify-signature/
  4. https://ubuntu.com/tutorials/how-to-verify-ubuntu
  5. https://tails.net/install/expert/index.en.html#verify-key
  6. https://calyxos.org/install/verify/#additional-verification
maltfield commented 5 months ago

Note: This ticket was "moved" here from the prior ticket opened in the session-desktop repo: