Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please get release key cross-signed & advertise it #25

Open
jonathancross opened this issue Oct 15, 2024 · 1 comment
Open

Please get release key cross-signed & advertise it #25

jonathancross opened this issue Oct 15, 2024 · 1 comment

Comments

@jonathancross
Copy link

jonathancross commented Oct 15, 2024

I am trying to verify the PGP signature on a release.
It was signed with key DAA24D878B8D36C90120A897CA02DAC12DAE2D0F which was just created in June and has no cross signatures. DuckDuckGo doesn't know anything about this key.

I see Woodser has a key in this repo, but that key has nothing to do with this key above.

Can you please cross-sign each other's keys and advertise the proper haveno-reto signing key fingerprint in a few places?

Ideally get some prominent people in Monero to also certify the key.

Ideally all commits should also be gpg signed.

Why?

We should not trust GitHub / Microsoft infrastructure.
If something goes wrong, there should be a digitally signed audit trail.

Thanks!

@boldsuck
Copy link

I got it from here: https://haveno-reto.com/reto_public.asc
You can also request the key or fingerprint in their Haveno-reto SimpleX group.

@woodser will not sign any third-party Haveno mainnet instances. He only develops test- (stagenet) software.
Other prominent people in Monero community, maybe.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants