Bitcoin Gold issues critical advisory after spotting suspicious files in Github repo

Discussion in 'other security issues & news' started by itman, Nov 27, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://www.scmagazine.com/bitcoin-...et-installer/article/709678/#disquos-comments
     
  2. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,402
    We have the same issues with all the crypto coins. Take BTC as an example. Folks are using software to store coins that are valued at ~ 10K. Some people have multiple coins with great value overall. Yet, they don't take the time to verify a simple sha256? If available its much better to use a GPG verify process because it prevents a fake website from hosting not only the bad files, but also a FAKE sha256 sum. Think about it. If I host a fake site and give you a fake sha256 to my bogus file then surprise it confirms and you think you have the real deal. Not so though. However; with the GPG signed file ONLY the private key for the signing set can make the signature test true. MUCH better authentication.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.