-
binaryFateErCiccione[m] done. Cannot flush CF cache though, I don't have access yet.
-
ErCiccione[m]Thanks 🙂. No worries, shouldn't be a problem for these updates
-
ErCiccione[m]Reddit post with the list of the major updates: reddit.com/r/Monero/comments/esqso7…rg_updated_new_simplified_accepting
-
binaryFategreat job
-
ErCiccione[m]:)
-
sarangHooray, the blag post is up!
-
ErCiccione[m]
-
ErCiccione[m]luigi1111 ^
-
xmr-prdginovker opened issue #1044: Merchants Page is a little borked on Mobile
-
xmr-pr
-
Mochi101If someone is able to compromise the getmonero.org server and put their own binary on it, wouldn't it also be simple enough for them to change the verification hashes on the web page to match the binary that they put onto the server?
-
Mochi101I guess that's why one has to download the signing key hey.
-
sarangI believe someone mentioned the files are hosted separately from the hashes, but yes, that's the point of checking signatures
-
sarangThen there's the extra layer of being able to look at other trusted build reproductions
-
sarangWhich ensures that the entity doing the signed hashes used the expected code to build the binaries
-
sarangSimply downloading, hashing, and comparing (without signature checks) would only avoid some accidental file corruption during download
-
Mochi101Yeah, it's a really involved process hey.
-
sarangFortunately moneromooo built a tool to help with the verification process
-
sarang(of course, you have to trust the tool does what you expect)
-
sarang(but the tool is open source!)
-
rottensoxwhat tool is that? sarang.
-
rottensoxmight be helpful for next el monero episode. someone mentioned a web interface to verify hashes but i sort of dislike the idea of trusting a site instead of cli, or an open source tool, as you mention.
-
sarangHere's the tool: github.com/moneromooo-monero/monero-update
-
sarangDisclaimer: I have not used it personally
-
rottensoxthanks for sharing.
-
sarangWould need to ask moneromooo for any specific further details
-
sarangIt was created after the download server breach
-
rottensoxwasn't aware of its creation. will check the documentation out and give it a go so i have a more informed stance when discussing it on the pod.