Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Privacy
  3. How important is it to verify a signature (of say Mullvad Browser)?

How important is it to verify a signature (of say Mullvad Browser)?

Scheduled Pinned Locked Moved Privacy
privacy
19 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • zdhzm2pgp@lemmy.mlZ [email protected]

    Thank you for taking the time to write all that! I did do what you described, but the RSA key I got at the end was different from what Mullvad's webpage says, which is the same as what you put, I think: 6131 . . . etc.

    X This user is from outside of this forum
    X This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #10

    Good signature from "Tor Browser Developers (signing key) <[email protected]>" [full]

    Did you see this notification at all when you verified the key signature?

    zdhzm2pgp@lemmy.mlZ 1 Reply Last reply
    0
    • X [email protected]

      Good signature from "Tor Browser Developers (signing key) <[email protected]>" [full]

      Did you see this notification at all when you verified the key signature?

      zdhzm2pgp@lemmy.mlZ This user is from outside of this forum
      zdhzm2pgp@lemmy.mlZ This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #11

      Yes, I got:

      Good signature from "Tor Browser Developers (signing key) <[email protected]>" [full]

      Does that mean it's ok? Maybe Mullvad just needs to update their website?

      1 Reply Last reply
      0
      • zdhzm2pgp@lemmy.mlZ [email protected]

        Because it's kind of hard! Even if I follow their instructions. Maybe I'm just dumb . . . ๐Ÿ™

        K This user is from outside of this forum
        K This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #12

        If it is hard, it is usually unnecessary. Unless it is a critical software (like a firmware update), or you suspect that somebody manipilates your traffic (which is highly unlikely on https sites)

        S 1 Reply Last reply
        0
        • zdhzm2pgp@lemmy.mlZ [email protected]

          Because it's kind of hard! Even if I follow their instructions. Maybe I'm just dumb . . . ๐Ÿ™

          zdhzm2pgp@lemmy.mlZ This user is from outside of this forum
          zdhzm2pgp@lemmy.mlZ This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #13

          From Mullvad support:

          1 Reply Last reply
          0
          • K [email protected]

            If it is hard, it is usually unnecessary. Unless it is a critical software (like a firmware update), or you suspect that somebody manipilates your traffic (which is highly unlikely on https sites)

            S This user is from outside of this forum
            S This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #14

            Not necessarily traffic. Often download sites use mirrors to serve you the download. Sometimes those links are provided via a CDN which can be forced to comply to LEA or some other static hosted mirrors which are often hosted by others. The second part is more likely on community managed software.

            So either traffic or the server/CDN behind the link. Happened before.

            1 Reply Last reply
            0
            • zdhzm2pgp@lemmy.mlZ [email protected]

              Because it's kind of hard! Even if I follow their instructions. Maybe I'm just dumb . . . ๐Ÿ™

              A This user is from outside of this forum
              A This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #15

              You should always verify signature and hash for any software you are installing but also keep in mind that if someone was really trying to send you a malicious download then there's good chance that they will also deliver you a malicious signing key and hash. And there is really no good solution. If it is critical you can try to get signings keys from different places and with different IPs and maybe even different devices but pick and choose how long do you want to go down this rabbit hole.

              1 Reply Last reply
              0
              • dsklnsadog@lemmy.dbzer0.comD [email protected]

                The important is to do it the first time. Then just upgrade the app.

                A This user is from outside of this forum
                A This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #16

                That's a bad advice you don't know how they are updating it. If it is added in the repo then package manager will check the signing key but if it is an in app update then that may not be verifying the new package and if someone is doing MITM they can switch it up

                dsklnsadog@lemmy.dbzer0.comD 1 Reply Last reply
                0
                • A [email protected]

                  That's a bad advice you don't know how they are updating it. If it is added in the repo then package manager will check the signing key but if it is an in app update then that may not be verifying the new package and if someone is doing MITM they can switch it up

                  dsklnsadog@lemmy.dbzer0.comD This user is from outside of this forum
                  dsklnsadog@lemmy.dbzer0.comD This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #17

                  I donโ€™t think itโ€™s bad advice for most people. Maybe itโ€™s just bad advice for your treat model

                  A 1 Reply Last reply
                  0
                  • dsklnsadog@lemmy.dbzer0.comD [email protected]

                    I donโ€™t think itโ€™s bad advice for most people. Maybe itโ€™s just bad advice for your treat model

                    A This user is from outside of this forum
                    A This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #18

                    Yeah I guess so. Due to SSL if you want to perform successful MITM you'll need to have control of DNS and must have rootCA installed on there system/browser. And if it is a supply chain attack where source it self corrupted then there is no hope.

                    1 Reply Last reply
                    0
                    • zdhzm2pgp@lemmy.mlZ [email protected]

                      Because it's kind of hard! Even if I follow their instructions. Maybe I'm just dumb . . . ๐Ÿ™

                      communism@lemmy.mlC This user is from outside of this forum
                      communism@lemmy.mlC This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #19

                      What's your OS and how are you installing it? It'd be normal for a package manager to check this for you.

                      1 Reply Last reply
                      0
                      • System shared this topic on
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups