-
-
Notifications
You must be signed in to change notification settings - Fork 515
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Software security for ImageGlass #97
Comments
It'd be great if ImageGlass' installer was signed, giving an additional layer of security to the existing method of comparing the SHA1 checksum provided at http://www.imageglass.org with the github.com EXE release. System info:
Other info:Lately, some open source projects' websites were compromised (see e.g. HandBrake), having their installers infected. Having a signed installer gives confidence that this executable wasn't tampered with by a malicious actor. |
Hi @Abdull Thanks for the information. As you can see, there is no ads in the app and the website because i don't want to interrupt user experience. |
Thank you for reopening this issue. I'm happy to donate and wish you lots of follow-up donators in order to realize this request. |
Thanks @Abdull for the donation. |
updated: what's next: |
Forgive the answer if i say something incorrect but moving the link to installer on github/releases mantaining the cecksum on https://imageglass.org/ wouldn't improve the security? |
Hi @cela96 :) |
From Yawn:
Can you please use HTTPS (letsencrypt.org) and / or sign your Windows executable?
The text was updated successfully, but these errors were encountered: