Hi all- GPG4WIN-5.0.2 validation on different pages

Hi-

Re: request to unify locations of verification files GnuPG4Win–

There is an .asc file in 1 place, a .sig file in another, the fingerprint on another, the 2nd fingerprint for the actual gnupg.org on another page for Werner Koch, and the current fingerprint on another page separate from the page that has the up to year 2016 etc. fingerprint.

Can someone at some point, please consider moving all the links to the same page without hyperlinking to all of them in disparate places? Even if the 1 page has all the hyperlinks grouped together to make the validation. This is what it is like to use the support page to do it.

You will probably hit me with, where are all those at? If you want to ask, go ahead, and I will try to give you a list that you can validate with virustotal.com.

Having said that, I just wanted to compliment you for the cool software that makes my job so much easier to maintain a trust level on apps that don’t come from a domain like … where they may not validate things by GPG.

I tried and think too i did convince someone, that at least I think, it is indispensable to have this level of verification, especially for this 1 tool, from with which to verify the rest!

This tool makes it so easy to do this verification for a couple software apps, that unbeknownst before today, many people may not know how much OCD goes into this sort of thing to keep open source locked up and tidy (and i don’t know the half of it).

Thanks so much all,

j.

Hi @cybertron,

thanks for your feedback!

Towards your suggestion to link all verification files from one place:
Partly it is the idea that they are not centrally linked.

From Gpg4win we link Gpg4win - Check Integrity prominently (as far as I can see) and that is pretty clear on that using the code signature that Microsoft’s Windows trusts, is a very good method to verify the Gpg4win binary package. More is rarely needed, for this cases we link Gpg4win/CheckIntegrity - GnuPG wiki with more instructions. Can you tell me where those instructions can be improved or do not work for you?

The problem with linking everything from one place is, that it is a single place. If there ever would be a strong attack on that single place, other channels of trust are needed.

On the other hand, we want people to understand the several methods of adding more trust (or verification hints). To be frank, this I’ll find it difficult to explain, so it is more for people that want to be advanced users or to learn about the different methods.

Best Regards,
Bernhard