Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No more hash on Twitter? #644

Open
baro77 opened this issue Sep 1, 2023 · 2 comments
Open

No more hash on Twitter? #644

baro77 opened this issue Sep 1, 2023 · 2 comments

Comments

@baro77
Copy link

baro77 commented Sep 1, 2023

It's a pity, it was an extra security 'cause compromising BIP39 Tool was meaning to compromise the repo but also your twitter account (the bip39-standalone.html compiled from a compromised source couldn't have matched the right hash): now it's "enough" to compromise your GitHub... hope you'll step back to the former procedure involving another platform as well. Thanks!

@ghscuuo
Copy link

ghscuuo commented Sep 1, 2023

I verify [edit: standalone html file integrity] by uploading the well-exercised old-faithful 0.5.4 standalone here:
https://www.virustotal.com/gui/file/8b8e3c1be03501f57e395781de8a59fd553808e1eb1278710bd7b96dacb6d0f6

(Can also check the pgp signature. https://github.com/iancoleman/bip39/releases/tag/0.5.6)

@baro77
Copy link
Author

baro77 commented Sep 2, 2023

virustotal check is meaningless, since it wouldn't discover, for example, biases in RNG

pgp signature check is less immediate than athe comparison of two hashes

just imho

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants