mvdheuvel1983 (OP)
Sr. Member
Offline
Activity: 1246
Merit: 390
🌀 Cosmic Casino
|
The general advice is the a Bitcoin tool such as a wallet is okay to use if it is open-source. Aside this there are crypto companies that post their open source code online. I consider my self a skeptic to a degree and I know that there is always the possibility that these companies could post the open source code online but run a different code on your device. There's also another possibility that it could be tampered with during transit.Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
|
|
|
|
_act_
Legendary
Offline
Activity: 1106
Merit: 1332
Lightning network is good with small amount of BTC
|
If you are not a developer, you can not know it, only developers can be able to completely know if a code is completely open source or not. For wallets, you can ask on this forum. You can check this website also: https://walletscrutiny.com/If you are a developer, the open source wallets leave their code public on GitHub.
|
|
|
|
AbuBhakar
|
|
September 17, 2023, 01:14:53 PM |
|
Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
Use the forum to help you verify it. There’s a lot of good developer here on the technical board that can help you verify the code. There’s no way to verify it if you didn’t know how to read a code since you will need to determine how it was coded to verify if the code use is safe for user safety. I was wondering if there’s a specifi code line that a non-developer can use a reference to watch out if the code is safe or not.
|
| | | . Duelbits│SPORTS | | | | ▄▄▄███████▄▄▄ ▄▄█████████████████▄▄ ▄███████████████████████▄ ███████████████████████████ █████████████████████████████ ███████████████████████████████ ███████████████████████████████ ███████████████████████████████ █████████████████████████████ ███████████████████████████ ▀████████████████████████ ▀▀███████████████████ ██████████████████████████████ | | | | ██ ██ ██ ██
██ ██ ██ ██
██ ██ ██ | | | | ███▄██▄███▄█▄▄▄▄██▄▄▄██ ███▄██▀▄█▄▀███▄██████▄█ █▀███▀██▀████▀████▀▀▀██ ██▀ ▀██████████████████ ███▄███████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ▀█████████████████████▀ ▀▀███████████████▀▀ ▀▀▀▀█▀▀▀▀ | | OFFICIAL EUROPEAN BETTING PARTNER OF ASTON VILLA FC | | | | ██ ██ ██ ██
██ ██ ██ ██
██ ██ ██ | | | | 10% CASHBACK 100% MULTICHARGER | | │ | | | | │ |
|
|
|
Cantsay
|
|
September 17, 2023, 01:17:17 PM |
|
If you can read codes then you’ll be able to read through to see if there’s any back door, but if you’re not you could take them to someone who can and if they confirm that it’s safe then you can proceed to compiling them yourself if you don’t trust the app that was uploaded or if you’re skeptical about using the software since they can use a different code for it.
I don’t know if it’s practical but you could watch a few tutorials on how to work your way through compiling the files depending on the language to an .exe file. I have never tried it myself but it’s never bad to learn something new.
|
| | | | | | | ███▄▀██▄▄ ░░▄████▄▀████ ▄▄▄ ░░████▄▄▄▄░░█▀▀ ███ ██████▄▄▀█▌ ░▄░░███▀████ ░▐█░░███░██▄▄ ░░▄▀░████▄▄▄▀█ ░█░▄███▀████ ▐█ ▀▄▄███▀▄██▄ ░░▄██▌░░██▀ ░▐█▀████ ▀██ ░░█▌██████ ▀▀██▄ ░░▀███ | | ▄▄██▀▄███ ▄▄▄████▀▄████▄░░ ▀▀█░░▄▄▄▄████░░ ▐█▀▄▄█████████ ████▀███░░▄░ ▄▄██░███░░█▌░ █▀▄▄▄████░▀▄░░ █▌████▀███▄░█░ ▄██▄▀███▄▄▀ ▀██░░▐██▄░░ ██▀████▀█▌░ ▄██▀▀██████▐█░░ ███▀░░ | | | | |
|
|
|
SquirrelJulietGarden
|
|
September 17, 2023, 01:20:29 PM |
|
I consider my self a skeptic to a degree and I know that there is always the possibility that these companies could post the open source code online but run a different code on your device. There's also another possibility that it could be tampered with during transit.Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
You have to be a professional coder to be able to verify source code of Bitcoin wallet software. If you are like me, you have to rely on reviews from community including professional coders, Bitcoin developers on wallet softwares. You can use websites like https://walletscrutiny.com/ that is from a professional Bitcoin developer. Or some review websites like https://www.cryptowisser.com/wallets/
|
| CASINOBET | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ |
██████████▄▄▄▄██▄ ████████████████▀ ███████████████▀ ██████████████▀ █████████████▌ █████▄██████▌ ████▄███████ ███▐███████▌ ███████████
██████████ | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | | ████████
██████████▄▄ ███████████████ ██████████████▌ ██████████████ █████████████▌ █████████████ ████████████▌ ████████████ █████▀▀▀███▌ | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | | ████████ ▄██████████▄ ██████████████ ████████████████ █████████▒▒███████ █████████▒▒▒██████ █████████▒▒███████ ████████████████ ██████████████ ▀██████████▀ ▀▀▀▀▀▀▀▀ ████████ ██
| ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ULTIMATE DESTINATION FOR CRYPTO GAMING PLAY NOW |
|
|
|
BitMaxz
Legendary
Offline
Activity: 3472
Merit: 3204
Playbet.io - Crypto Casino and Sportsbook
|
Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
Most of the open source have public GPG keys, checksums, and signatures you can verify their integrity by verifying these. Sample Electrum if you download it from GitHub or their website it also provides a GPG signature you can verify it by using the GPG tool. Other open-source codes also provide checksum files you will need a checksum tool to verify its authenticity there are some guides out there on how to verify checksum or check this link below. - https://codesigningstore.com/how-to-check-file-checksum Another thing is you can directly build it from the source if you don't trust the file that you downloaded or installed.
|
|
|
|
Z-tight
Legendary
Offline
Activity: 1078
Merit: 1114
Wheel of Whales 🐳
|
|
September 17, 2023, 01:45:00 PM |
|
The general advice is the a Bitcoin tool such as a wallet is okay to use if it is open-source.
Open source code or software is recommended, but it doesn't mean they are safe by default, it means that the code can be reviewed, while bugs and attacks can be found easily and quicker. If it is a source code that has been reviewed by a lot of developers in the community, you can tick it as safe. companies could post the open source code online but run a different code on your device.
If you have downloaded the original software and not a malicious one, and you've also verified your download; then you can be sure you are running the original software. If it is a well reviewed software, then if anything is slipped into its code in any of its new update, it will be easily identified and users will be warned not to make the update locally on their device. there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
The only way is by verifying it, if you don't have the skill to do it, then use software that is well reviewed and recommended by the community.
|
|
|
|
Faisal2202
|
|
September 17, 2023, 02:47:28 PM |
|
The general advice is the a Bitcoin tool such as a wallet is okay to use if it is open-source. Aside this there are crypto companies that post their open source code online. I consider my self a skeptic to a degree and I know that there is always the possibility that these companies could post the open source code online but run a different code on your device. There's also another possibility that it could be tampered with during transit.Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
I think you can solve this skepticism by comparing the GPG code (signature code which is used to verify that the code is not tampered with) or hashes. I hope you can do that. Otherwise you simply have to find the resource code of the product you are using and then can compare that code with the code which the publishers have published. You should take some products as an example.
|
|
|
|
pooya87
Legendary
Offline
Activity: 3668
Merit: 11107
Crypto Swap Exchange
|
Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
Most of the open source have public GPG keys, checksums, and signatures you can verify their integrity by verifying these. Sample Electrum if you download it from GitHub or their website it also provides a GPG signature you can verify it by using the GPG tool. Technically the thing you are verifying using GPG signatures is the authenticity of the binary or in simple terms you make sure that the binary is released by the person who owns that key. It does NOT tell you whether the binary has anything to do with the open source code you saw on the GitHub. In order to know whether the binary is actually built from the source code you saw, the project has to support what's called "deterministic builds"[1]. This means no matter who compiles the code and where, they should all get the same exact binaries. That way different people could verify that the binary is indeed built from the source code we see by simply comparing the checksums. Electrum supports deterministic builds by the way. [1] https://en.wikipedia.org/wiki/Reproducible_builds
|
|
|
|
_act_
Legendary
Offline
Activity: 1106
Merit: 1332
Lightning network is good with small amount of BTC
|
|
September 17, 2023, 04:13:31 PM |
|
I think you can solve this skepticism by comparing the GPG code (signature code which is used to verify that the code is not tampered with) or hashes. I hope you can do that. Otherwise you simply have to find the resource code of the product you are using and then can compare that code with the code which the publishers have published. You should take some products as an example.
You are getting it wrongly. GPG or PGP or anything that we call a way to verify that we downloaded the right app and not the fake one is not a way to know that a software is open source or close source. Assuming I downloaded Electrum and verify its signature, I will know that Electrum site has not been compromised and that the wallet I downloaded from the Electrum site is from the Electrum developer. If Electrum site is compromised and the hacker that compromised it changed the original Electrum app to fake apps, I will be able to know that it is fake if the PGP signature fails.
|
|
|
|
m2017
Legendary
Offline
Activity: 2030
Merit: 1413
Playbet.io - Crypto Casino and Sportsbook
|
|
September 17, 2023, 05:28:56 PM |
|
The general advice is the a Bitcoin tool such as a wallet is okay to use if it is open-source. Aside this there are crypto companies that post their open source code online. I consider my self a skeptic to a degree and I know that there is always the possibility that these companies could post the open source code online but run a different code on your device. There's also another possibility that it could be tampered with during transit.Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
I, too, have always had similar skepticism about open source applications, which for some reason everyone perceives as a panacea for possible backdoors from a wallet provider. I also have doubts that a cryptocompany may provide completely different source code for testing on specialized resources, such as github. Also, it always seemed strange to me that if the source code is open, then someone necessarily checks this code. What if everyone hopes that the other will do it and in the end no one checks? Do people have nothing better to do than check the source code of every application? In this case, I am ready to trust completely only myself, but I don't have the skills to independently check the source code of applications. So how can someone like me, who are the majority, check the source code and make sure that it is the right source code and not a fake? In general, I support OP’s questions.
|
|
|
|
vv181
Legendary
Offline
Activity: 1932
Merit: 1273
|
|
September 17, 2023, 06:55:53 PM |
|
Also, it always seemed strange to me that if the source code is open, then someone necessarily checks this code. What if everyone hopes that the other will do it and in the end no one checks? Do people have nothing better to do than check the source code of every application? In this case, I am ready to trust completely only myself, but I don't have the skills to independently check the source code of applications. So how can someone like me, who are the majority, check the source code and make sure that it is the right source code and not a fake? In general, I support OP’s questions. The motivation of others to check an open source project is because they simply use or build something from the particular project, in consequence, they are encouraged to eventually check the code. Furthermore, the question arises about what if there isn't anyone even checking the code is a valid one, hence, open source does not mean it would be automatically secure and trusted. It is still necessary to use a project that has gained trust within the open source community, so there are many eyes that scrutinise the project in case something goes wrong. It also helps to those who can not manually check and comprehend the code by themselves.
|
|
|
|
OgNasty
Donator
Legendary
Offline
Activity: 4956
Merit: 4988
Leading Crypto Sports Betting & Casino Platform
|
|
September 17, 2023, 07:10:31 PM |
|
As others have already said you can use a checksum to verify the authenticity of a file. The best way is always to obtain the source code from the official trusted source and build it yourself though. It’s not even a very difficult task, you just need to get in the habit of doing it. I myself usually don’t go through the extra steps out of laziness, but it doesn’t take a lot of time or effort so it’s a good habit to get into.
|
..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
BlackHatCoiner
Legendary
Offline
Activity: 1736
Merit: 8456
Fiatheist
|
|
September 17, 2023, 07:25:48 PM |
|
I consider my self a skeptic to a degree and I know that there is always the possibility that these companies could post the open source code online but run a different code on your device. When software is said to be open-source, it means you can verify this yourself. All you need to do is download the repository, and follow the instructions, which more or less go as following: Step 0: Have a compiler (i.e., gcc). Step 1: Install some libraries (the instructions will give you the precise command to enter in terminal). Step 2: Compile. Probably with some Makefile, which is essentially an automated way to build the program. Step 3: Verify the binaries' checksum (as you would in any case). This way you can verify that the binaries the company has in their main page are indeed not altered.
|
|
|
|
JunaidAzizi
|
|
September 17, 2023, 07:35:31 PM |
|
The general advice is the a Bitcoin tool such as a wallet is okay to use if it is open-source. Aside this there are crypto companies that post their open source code online. I consider my self a skeptic to a degree and I know that there is always the possibility that these companies could post the open source code online but run a different code on your device. There's also another possibility that it could be tampered with during transit.Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
It is possible to verify the integrity of open source code that is running on your device is the same as the published. there are two ways through which it can be verified. The one is to compile the code yourself. This involves the compiler converting the source code into machine code that can be executed by your computer, If you are able to compile the code successfully then you are confident that the code is authentic. The second one is a signature tool that verifies the integrity of open-source code. A signature tool can generate a digital signature for a piece of software. this digital signature can then be used to verify that the software has not been tampered with.
|
|
|
|
Hamza2424
Legendary
Offline
Activity: 1190
Merit: 1105
Payment Gateway Allows Recurring Payments
|
|
September 17, 2023, 08:17:06 PM |
|
The general advice is the a Bitcoin tool such as a wallet is okay to use if it is open-source. Aside this there are crypto companies that post their open source code online. I consider my self a skeptic to a degree and I know that there is always the possibility that these companies could post the open source code online but run a different code on your device. There's also another possibility that it could be tampered with during transit.Is there anyway that I can verify the integrity of open-source code and ensure that the code running on your device matches the published code?
OP is to be mentioned first I think, this topic fits In technical discussion more effectively, Besides that IMO, as your concerns are legit by participation in the community discussion where people are likely using it, you can get engaged to authenticate the integrity as if anything wrong happens someone will post about it and you can get a pre-alert as well. Secondly, I think tampered with during transit can be authenticated with digital signatures and most of the time it works well. Compiling the code by yourself and other ways may not be helpful for a day-to-day user who is not familiar with such things., so as above I had mentioned by reading the feedback and reviews, he can judge. Anyway, that was I nice topic for today's list haha I can read others and obtain some good insights as well.
|
|
|
|
Medusah
|
|
September 17, 2023, 08:30:27 PM |
|
The second one is a signature tool that verifies the integrity of open-source code. A signature tool can generate a digital signature for a piece of software. this digital signature can then be used to verify that the software has not been tampered with. Digital signatures are used to verify that the binaries were not tampered during file transfer, but not that the source code shown corresponds to the binaries. To verify that, you download the source code and build it yourself. And then check for digital signature.
|
|
|
|
Upgrade00
Legendary
Online
Activity: 2254
Merit: 2401
Playgram - The Telegram Casino
|
|
September 17, 2023, 08:43:05 PM |
|
So how can someone like me, who are the majority, check the source code and make sure that it is the right source code and not a fake? In general, I support OP’s questions.
I think it's down to having the option. If the code source is closed then no one can check what's going no regardless of the skills you possess. If it's open source the devs are aware that what they do is publicly available and there will at least be a couple of their usersbt verify that. The question does not negate the need to use open source but just shows that not everyone can effectively utilize the feature.
|
|
|
|
▄▄███████▄▄███████ ▄███████████████▄▄▄▄▄ ▄████████████████████▀░ ▄█████████████████████▄░ ▄█████████▀▀████████████▄ ██████████████▀▀█████████ █████████████████████████ ██████████████▄▄█████████ ▀█████████▄▄████████████▀ ▀█████████████████████▀░ ▀████████████████████▄░ ▀███████████████▀▀▀▀▀ ▀▀███████▀▀███████ | ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ Playgram.io ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | ▄▄▄░░ ▀▄ █ █ █ █ █ █ █ ▄▀ ▀▀▀░░
| │ | ▄▄▄███████▄▄▄ ▄▄███████████████▄▄ ▄███████████████████▄ ▄██████████████▀▀█████▄ ▄██████████▀▀███▄██▐████▄ ██████▀▀████▄▄▀▀█████████ ████▄▄███▄██▀█████▐██████ ██████████▀██████████████ ▀███████▌▐██▄████▐██████▀ ▀███████▄▄███▄████████▀ ▀███████████████████▀ ▀▀███████████████▀▀ ▀▀▀███████▀▀▀ | | │ | ██████▄▄███████▄▄████████ ███▄███████████████▄░░▀█▀ ███████████░█████████░░█ ░█████▀██▄▄░▄▄██▀█████░█ █████▄░▄███▄███▄░▄██████ ████████████████████████ ████████████████████████ ██░▄▄▄░██░▄▄▄░██░▄▄▄░███ ██░░░█░██░░░█░██░░░█░████ ██░░█░░██░░█░░██░░█░░████ ██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████ ███████████████████████ ███████████████████████ | | │ | ► | |
[/
|
|
|
franky1
Legendary
Offline
Activity: 4438
Merit: 4821
|
|
September 17, 2023, 09:17:08 PM |
|
when code is available on things like github. people (who dont have to be developers) can compile their own .exe file from that source code(easy tutorials are available)
they can also then look at the file hash of the compiled file to see it if matches file hashes of other already compiled .exe files attributed as the same version. and if it matches they can submit a comment that they too have matched the sourcecode to the .exe and the hashes match, thus one level of independently verifying the code matches the file and give independent opinion to other users that the promoted exe is legit too
i say this because: sometimes there are 'open source' projects that are wrote by small groups. compiled by the same group and promoted by the same group. with no independent outside review/check thus people end up blindly trusting a small centralized group
the whole point is not just that the source code is open to view. but also that it should be independently reviewed at code level and independently validated at compile level
another level of integrity of open source is not just that its openly readable. but also that making improvements to it should not be closed off
|
I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER. Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
|
|
|
hatshepsut93
Legendary
Offline
Activity: 3038
Merit: 2162
|
|
September 17, 2023, 11:16:23 PM |
|
The general advice is the a Bitcoin tool such as a wallet is okay to use if it is open-source.
No it's not. The general advice is that closed source wallets are bad, but this doesn't make all open source good. If you can't review the wallet code yourself, if no one that you trust has reviewed it, then it's not too different from a closed source. Like, there's less chance that someone would put backdoors into an open source wallet, because it's possible to spot it, but this doesn't mean that no one will try such thing.
|
|
|
|
|