Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please cryptographically sign OsmAnd MapCreator releases (eg PGP) #900

Open
maltfield opened this issue Aug 29, 2024 · 0 comments
Open

Please cryptographically sign OsmAnd MapCreator releases (eg PGP) #900

maltfield opened this issue Aug 29, 2024 · 0 comments

Comments

@maltfield
Copy link

Description

Currently it is not possible to verify the authenticity or cryptographic integrity of OsmAnd MapCreator because the releases are not cryptographically signed.

This makes it hard for OsmAnd MapCreator users to safely obtain the MapCreator software, and it introduces them to watering hole attacks.

Steps to Reproduce

  1. Go to the https://osmand.net/
  2. Scroll down to footer and click Downloads link to https://osmand.net/docs/versions/free-versions
  3. Click OsmAnd MapCreator link to https://osmand.net/docs/versions/map-creator
  4. ???
  5. Get confused and open ticket

Expected behavior: [What you expected to happen]

A few things are expected:

  1. I should be able to download the OsmAnd PGP key out-of-band from popular third-party keyservers (eg https://keys.openpgp.org/)
  2. I should be able to download a cryptographic signature of the release (or, better, the releases' digest file, such as a SHA256SUMS.asc file) along with the release itself
  3. The downloads page itself should include a link to the documentation page that describes how to do the above two steps

Actual behavior: [What actually happened]

There's just literally no information on verifying downloads, and it appears that it is not possible to do so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant