Bitcoin Forum
May 28, 2024, 07:39:48 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: https downloads + SHA Checksums  (Read 765 times)
Slingshot (OP)
Sr. Member
****
Offline Offline

Activity: 616
Merit: 250


View Profile
October 22, 2013, 04:51:41 AM
Last edit: October 22, 2013, 05:04:11 AM by gmaxwell
 #1

An Important Message to all Crypto-Currency DEVELOPERS*


 Sadly even Bitcoin's Windows (exe) ~9MB download page is NOT secure (http).

 This is simply NOT Acceptable Anymore.

 See the next links for more on this:

Verify release signatures
http://bitcoin.org/en/download

and here is what "Verify release signatures" leads to
http://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.8.5/SHA256SUMS.asc/view


The UNSECURE Bitcoin download page!
The Bitcoin Download for Windows (exe) ~9MB download page:
http://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.8.5/bitcoin-0.8.5-win32-setup.exe/download

  it's merely http (unsecure).

 Secure = https


 Again, starting now this is simply no longer acceptable. Too much is riding on Bitcoin. And ALL the other Crypto-Currencies for that matter to risk bad results, and worse still public reports of any of them anymore.

 At least that's what I believe, and being a most recent victim of a bad resulting download (see the link at the bottom of this post) I wont rest easy until ALL DEVELOPERS get their acts together on these two most serious of issues!



RECAP:

1. All download pages for all Qt's and other Wallets need to be https

2. All Crypto-Currency wallets for every crypto-currency needs to also offer SHA-256 Checksum details to use together with an end user's very simple and easy to use SHA-256 Checksum Utility in order to verify the downloaded item is not compromised nor corrupted.

  BTW: The Gpg4win with GnuPG  is just too painful  to use for many ordinary users to bother with, imo. Here the KISS theory would most be wise (keep it simple stupid/kiss) with everyone going to the SHA-256 Checksum, and sticking with it going forward. And after all SHA-256 is what Bitcoin is based on. So at least that's okay right now. But Bitcoin.org and all third party wallets need to do both to measure up to reasonable levels of security. Next stop for me is Bitcoin.org...




 Simply put: I wont ever utilize MEGA for anything again. Especially not Downloads.



(not required reading...)

RE: ***** VIRUS WARNING ***** @ MEGA's Unsecure Download site for Lucky7coin

https://bitcointalk.org/index.php?topic=315936.0



and


(not required reading, below is very much a repeat of the above text in this post, plus a bit more for other alt currencies)

An Important Message to all Crypto-Currency DEVELOPERS*

https://bitcointalk.org/index.php?topic=315938.0




Caveat empore
gmaxwell
Moderator
Legendary
*
expert
Offline Offline

Activity: 4186
Merit: 8435



View Profile WWW
October 22, 2013, 05:03:48 AM
 #2

This is a duplicate of a recent thread, and wasn't news. In the future, please take a moment to search before starting a new thread.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!