Bitcoin Forum

Bitcoin => Wallet software => Topic started by: jimbobway on June 13, 2019, 08:09:38 PM



Title: Is Bitcoin Core Code Signing Association Legit?
Post by: jimbobway on June 13, 2019, 08:09:38 PM
Downloaded core and saw the exe was signed by "Bitcoin Core Code Signing Association".

This is new and I haven't heard of it.  Is it legit?  Also found this website:

https://bitcoincorecodesigning.org/


Title: Re: Is Bitcoin Core Code Signing Association Legit?
Post by: BitMaxz on June 13, 2019, 08:27:29 PM
Where did you download the bitcoin core? I tried to search this site on google but no so much info about this site.

This is the correct website where you can download the bitcoin core https://bitcoin.org/en/download

You must verify this core if it is fake or not you can follow this guide from here https://bitcointalk.org/index.php?topic=1588906.0


Title: Re: Is Bitcoin Core Code Signing Association Legit?
Post by: TryNinja on June 13, 2019, 08:45:11 PM
I'm not sure about this website, but the signature from "Bitcoin Core Code Signing Association" is legit.

But still, don't trust. Verify. You can verify the file signature yourself: https://bitcoincore.org/en/download/ (see section "Verify your download")


Title: Re: Is Bitcoin Core Code Signing Association Legit?
Post by: jackg on June 13, 2019, 09:01:26 PM
Yeah it sounds like something a cryptography would name it as too ;D.

I'd sue for copyright if I thought I'd have a good case as that's what I'd have called it... My copy was signed by them so it's the same publisher.


Title: Re: Is Bitcoin Core Code Signing Association Legit?
Post by: pooya87 on June 14, 2019, 04:33:51 AM
if i am not mistaken this is the new certificate the bitcoin-core team has been using for their windows binary released. it is not important at all because you shouldn't pay attention to it and instead verify the PGP signature provided alongside the binaries you download. this certificate is only there to prevent windows to go crazy when you try to install bitcoin-core, without this certificate it would go crazy and issue a ton of warnings which can confuse newbies.

the website repository is here: https://github.com/bitcoincore-codesigning-association/bitcoincorecodesigning-dot-org and is owned by a bitcoin-core contributor https://github.com/jonasschnelli. so yeah it should be legit.