Bitcoin Forum
November 08, 2024, 02:57:15 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Cryptographically sign Bitcoin  (Read 767 times)
neptop (OP)
Sr. Member
****
Offline Offline

Activity: 314
Merit: 251


View Profile
June 20, 2012, 01:07:32 PM
 #1

Bitcoin is about wealth and money. One needs to be able to confirm that one doesn't receive a version of Bitcoin that has been maliciously modified. It would therefor be a good idea to sign the source code as well as the binary packages. This way one just needs to be sure that one gets the right public key once.

With such a key it would also be possible to get the binaries/source from somewhere else. So if the official website is being censored, but a user obtained or has access to the public key one could get it from Tor, I2P, Freenet, from a random other website and still be sure to have an official release.

Just have a developer or trusted person with a completely disconnected computer generate a keys on their. Move the public key to key servers (most of them sync anyways) and have him put together the official release (maybe again making sure that the code is the right one) there and create the signatures. Then just move it all out onto the interwebs and there you are. Really secure releases.

To make it really really secure one could of course have multiple parties doing the same thing. This, via a web of trust and public key signing would even allow it to make sure that the public key can be changed over time.

BitCoin address: 1E25UJEbifEejpYh117APmjYSXdLiJUCAZ
gmaxwell
Moderator
Legendary
*
expert
Offline Offline

Activity: 4270
Merit: 8805



View Profile WWW
June 20, 2012, 01:19:23 PM
 #2

Bitcoin is about wealth and money. One needs to be able to confirm that one doesn't receive a version of Bitcoin that has been maliciously modified. It would therefor be a good idea to sign the source code as well as the binary packages. This way one just needs to be sure that one gets the right public key once.

The source is signed too— it's included as part of the Linux 'binary' packages.


Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!