Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document PGP release signature usage on getsession.org/download #3078

Closed
1 task done
maltfield opened this issue Apr 13, 2024 · 6 comments
Closed
1 task done

Document PGP release signature usage on getsession.org/download #3078

maltfield opened this issue Apr 13, 2024 · 6 comments
Labels
enhancement New feature or request

Comments

@maltfield
Copy link

maltfield commented Apr 13, 2024

Is there an existing request for feature?

  • I have searched the existing issues

What feature would you like?

Document how to cryptographically verify downloads on the getsession.org download page

Expected behaviour

When I go to download the Session desktop client, I should also see instructions on how to verify the authenticity of the file after download and before install. Or, at least, a link to the document that describes this.

Actual behaviour

I see no mention about cryptographic authenticity verification on the download page

Steps to reproduce

  1. Go to https://getsession.org/download
  2. Click "Linux" (or whatever platform I'm on)
  3. See the AppImage is downloading
  4. Look around on page for the word "verify" or "PGP" or "GPG" or "signature"
  5. ???
  6. Get confused and open ticket

Anything else?

No response

@maltfield maltfield added the enhancement New feature or request label Apr 13, 2024
@maltfield
Copy link
Author

Note: This is not a support request asking for information on how to verify release signatures.

The only resolution to this ticket is by updating the getsession.org download page with the information (or a link-to the information) that documents how users can verify release signatures.

@maltfield maltfield changed the title Document PGP release signature usage Document PGP release signature usage on getsession.org/download Apr 13, 2024
@maltfield
Copy link
Author

maltfield commented Apr 13, 2024

Yes, so one solution to this ticket would be to update https://getsession.org/download with text that says:

"to verify the authenticity of this release with PGP, please see Verifying Signatures"

@yougotwill
Copy link
Collaborator

@maltfield Thanks for this comprehensive write up. Sorry to be a pain but would you mind moving this issue to the getsession.org repo https://github.com/oxen-io/session-website/issues

@maltfield
Copy link
Author

maltfield commented Apr 15, 2024

Ticket moved to oxen-io/session-website#36

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants