 |
October 06, 2026, 04:28:00 PM |
|
buwaytress is right, the instructions say download, verify, transfer, disconnect, with verification of the sha on a connected to internet machine, which verifies you got an okay download, but not (necessarily) what you open on the air gapped machine. Maybe include in the instructions that, after transferring to usb stick, it would be a good idea to run sha256sum on the usb file, and verify that it matches the sha in the release notes.
Other than that, I was really impressed by the level of care that went into making the RC verifiable, not just signed SHA256SUMS from four different signers, but github attestation, signed tag, reproducible build from docker so anyone can check for themselves that the html really does come from the tagged commit, etc. etc. I do have a couple questions/comments, though:
I dont understand where entropy comes into play here. The program doesnt generate any entropy itself, for example 100 d6 has about 100 × log2 6 = 258.5 bits of entropy, while 99 only has about 255.9 bits (slightly less than 256). Does the program check/warn about the entropy given to it?
Has anyone besides the people who signed the release rebuilt this themselves and checked that it matches?
The notes say that this is an RC, and recommend using it only for empty wallets or testnet/signet coins, etc., until a 1.0.0 is out, and I would heed that advice.
|