Page 1 of 1
GPG keys
Posted: Mon Jan 22, 2024 9:51 pm
by ravas
Where can I find the gpg key used to sign the hash file on the download page?
Re: GPG keys
Posted: Mon Jan 22, 2024 11:35 pm
by Woodstock
Do you mean other than the link on the download page, marked "Files integrity may be checked using
hash file"?
(that link is for 1.17.6, by the way)
Re: GPG keys
Posted: Mon Jan 22, 2024 11:52 pm
by jemima
It’s e.g. here
https://keyserver.ubuntu.com/pks/lookup ... 3a18042697 (though this of course means not that it has any trust).
Cheers,
jemima
Re: GPG keys
Posted: Mon Jan 22, 2024 11:55 pm
by ravas
Woodstock wrote: ↑Mon Jan 22, 2024 11:35 pm
Do you mean other than the link on the download page, marked "Files integrity may be checked using
hash file"?
(that link is for 1.17.6, by the way)
That hash file is *signed* with a gpg key, but I can't find the public key anywhere(on makemkv's website) that was used to sign that file. I did find the public key on Ubuntu's keyserver, but I need to find a key somewhere here on makemkv's website Mike's account or something so I can verify it's authenticity.
Re: GPG keys
Posted: Mon Jan 22, 2024 11:57 pm
by ravas
I did actually find this a while ago, but I was hoping to find the key somewhere on makemkv's website or Mike's profile in order to verify its authenticity before I add it to my keyring(for packaging as an RPM). Just trying to be thorough and do as much due diligence as I can.
Re: GPG keys
Posted: Tue Jan 23, 2024 3:36 am
by jemima
Yeah, clear, though I haven't found it there either.
Anyway, even then then it's trust would completely depend on TLS, which - given the broken CA system[0] - isn't really that much.
Regards,
Jemima
[0] Roughly some 150 root CAs in the typical browser bundles, many of them controlled by countries of questionable reputation, not to talk about an unknown (many thousands of?) number of intermediate CAs, which all can forge more or less anything (and did so in the past).
Re: GPG keys
Posted: Tue Jan 23, 2024 11:50 pm
by ravas
I suppose, but the more I can cross-reference the more I can be confident in.