If GPG/PGP, I figure RJ would be the one to do the signing, since he is doing the builds? Maybe? In any case, other than uploading the signing key to a public keyserver it would be nice if the key were released here on the mailing list too, just to provide an out- of-band (more or less) corroboration and to earn the keys a little more trust on people's keyring.
~RAWRR On Sat, 13 Sep 2014 06:37:38 +0200 "Sean M. Pappalardo - D.J. Pegasus" <spappala...@mixxx.org> wrote: >Holy crap, Garth is alive too?? How are you, man? > >On 09/12/2014 01:19 PM, Garth Dahlstrom wrote: >> There was a case of this a few years back with some similar >installer >> crap website (music-oasis.com <http://music-oasis.com>) was >ripping us >> off. I believe we told them to cut it out and they did. > >Ehm, not exactly. "Digital DJ Pro" is still listed on their site >with >1.78M downloads. I don't know if it's comforting or horrifying >that it >appears to be based on Mixxx 1.5.0. > >Anyway, I would like to formally hijack this thread to talk about >code >signing (on Windows at least.) I think we should definitely do it >in any >case because it protects against tampering with the executable >(and even >if someone builds it from source, they still can't sign it with >our >cert.) Plus it looks more professional than "We can't verify the >source >of this application." > >StartSSL.com offers 2-year code signing certs for $50 (personal >identity >validation.) > >Thoughts? > >Sincerely, >Sean M. Pappalardo >"D.J. Pegasus" >Mixxx Developer - Controller Specialist ------------------------------------------------------------------------------ Want excitement? Manually upgrade your production database. When you want reliability, choose Perforce Perforce version control. Predictably reliable. http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk _______________________________________________ Get Mixxx, the #1 Free MP3 DJ Mixing software Today http://mixxx.org Mixxx-devel mailing list Mixxx-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/mixxx-devel