Verify a download
Check that what you downloaded is what was published, in your browser or with the portable verifier.
This section is also part of the front page, where it sits in context with the rest.
Drop the file you downloaded here. It is hashed locally, in your browser, using the built-in WebCrypto API, so there is no upload and no server that could receive it. Read js/verify.js; that file is the whole implementation.
The stronger check: the signature
A hash proves the file matches a list. The signature proves the list came from the maintainer. Browsers cannot verify OpenPGP, so this part runs on your machine:
gpg --import veilvoice-signing-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS --ignore-missing
Signing key fingerprint. Check that gpg --verify names this
exact key, not merely “a good signature”:
download the public key. The
user ID is exactly tilas01, with no e-mail address attached.
Or let it do all of that for you
veilvoice verify is built into the program itself: it ships in
every release because veilvoice does, and it needs no installer
and no separate download. Open a terminal in the folder you downloaded to
and run it, or open the desktop application's verify tab
and drop the archive on the window. One press does all four steps:
- the signature over
SHA256SUMS; - the archive, against
SHA256SUMS; CONTENTS.sha256, againstSHA256SUMS;- every file you extracted, against
CONTENTS.sha256, and it names anything in that folder the release never published.
Step 4 is the one worth having. A hash over the archive tells you the zip is genuine; this tells you the program you are about to run is. Releases before v0.1.15 carry no contents list and are checked as far as step 2, which it says at the time.
If GnuPG is on your machine it is used as well: the key is added to your
keyring, gpg --verify is run, and what GnuPG said is shown.
The signature is then checked by two independent implementations. The
commands above are still printed for you to run yourself, because a
program telling you a download is genuine came out of that download,
only you typing them makes the answer independent of it.
Every one of those commands, written out with what each answer proves, sits with the release you are downloading: the whole check in one line, the signature over the hash list on its own, one file against that list, one file against a hash with no list at all, the desktop application's three slots, and the build that answers the harder question. Every command there is checked against the program's own help when the page is generated.