This is a ticket to request iodéOS to sign releases cryptographically. Please copy and paste this into GitLab, since it’s not possible for users to create bug reports or feature requests with the iodéOS project.
Description
Currently it is not possible to verify the authenticity or cryptographic integrity of the downloads from gitlab.iode.tech because the releases are not cryptographically signed.
This makes it hard for iodéOS customers to safely obtain the iodéOS software.
Steps to Reproduce
- Go to the iodéOS website iode[.]tech
- Click “iodéOS” in the navigation bar iode[.]tech/iodeos/
- Click “Install iodéOS for free” iode[.]tech/installation/
- Click “alternative way of installing iodéOS here” gitlab.iode[.]tech/ota/ota
- Click on your device (eg Pixel 8) gitlab.iode[.]tech/ota/release/-/tree/master/shiba
- Look for the release signature
- ???
Expected behavior: [What you expected to happen]
A few things are expected:
- I should be able to download the iodéOS release-signing PGP key out-of-band from popular third-party keyservers (eg https://keys.openpgp.org/)
- I should be able to download a cryptographic signature of the release (or, better, the releases’ digest file, such as a
SHA256SUMS.asc
file) along with the release itself - The downloads page itself should include a link to the documentation page that describes how to do the above two steps
Actual behavior: [What actually happened]
There’s just literally no information on verifying downloads, and it appears that it is not possible to do so.