that validated the file is the correct key and not a fishy one?
i'd say it's unlikely that an attacker compromised github to replace binaryfate's key without there having to be an accepted pull request for it. they would have to compromise getmonero.com as well, build all the binaries and sign with their own key. but you do have a point, it is not an easy issue
Yeah, definitely not easy, but still possible though. Anyway, I've binaryfait's key saved on a txt for reference...every time I cross check with it also. I'm a little paranoid, I know 😁
Обсуждают сегодня