Delivery-Date: Fri, 27 Feb 2015 07:44:16 -0500
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.1 required=5.0 tests=BAYES_00,DKIM_SIGNED,
	FREEMAIL_FROM,RCVD_IN_DNSWL_MED,T_DKIM_INVALID,T_RP_MATCHES_RCVD,
	URIBL_BLOCKED autolearn=ham version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [38.229.72.13])
	(using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id DEC461E04D8
	for <archiver@seul.org>; Fri, 27 Feb 2015 07:44:14 -0500 (EST)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id 9D0DE33C28;
	Fri, 27 Feb 2015 12:44:11 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id 2930233C21
 for <tor-talk@lists.torproject.org>; Fri, 27 Feb 2015 12:44:08 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at 
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id QUyQn4sRCWUm for <tor-talk@lists.torproject.org>;
 Fri, 27 Feb 2015 12:44:08 +0000 (UTC)
Received: from out1-smtp.messagingengine.com (out1-smtp.messagingengine.com
 [66.111.4.25])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client did not present a certificate)
 by eugeni.torproject.org (Postfix) with ESMTPS id 11D8533BFC
 for <tor-talk@lists.torproject.org>; Fri, 27 Feb 2015 12:44:08 +0000 (UTC)
Received: from compute1.internal (compute1.nyi.internal [10.202.2.41])
 by mailout.nyi.internal (Postfix) with ESMTP id 7E0D220A58
 for <tor-talk@lists.torproject.org>; Fri, 27 Feb 2015 07:44:03 -0500 (EST)
Received: from web5 ([10.202.2.215])
 by compute1.internal (MEProxy); Fri, 27 Feb 2015 07:44:04 -0500
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=fastmail.fm; h=
 message-id:x-sasl-enc:from:to:cc:mime-version
 :content-transfer-encoding:content-type:subject:date:in-reply-to
 :references; s=mesmtp; bh=sQbL0iCpXNw4dgsNVwaNNMqCfqo=; b=TdmsST
 OtPpLAwIH5pylm5fbHKStHr80pahzL7Q5DG0XRuyrx4f0rW0VYXwjENlTtUfyes5
 HfmSQJ3hS84p1wBBry+MJN/sjP/EcPGgR2JrfKqhWkN/h2iViy7YJctTjjHgfVq5
 FIp1zF4Unnuvl+ke/G2PLwuIKBWVASBKeAIy0=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=
 messagingengine.com; h=message-id:x-sasl-enc:from:to:cc
 :mime-version:content-transfer-encoding:content-type:subject
 :date:in-reply-to:references; s=smtpout; bh=sQbL0iCpXNw4dgsNVwaN
 NMqCfqo=; b=avCVDi8F1pxi/EM6ZvqfYu5rFmlmgCIufZhc3IfNFosG4yjD+f8F
 PM+pa6s4K63WiVIEVVLSbbOrL146GUEFMqOp/ZYwp7wHEhOZyHXxzeKl5Qz2ZMra
 7GxGhpTTXDjVmyYnLIfli6IQSSUA/b6UtUTr85dnk90hndNkRSTORfM=
Received: by web5.nyi.internal (Postfix, from userid 99)
 id 3CB56A665DC; Fri, 27 Feb 2015 07:44:04 -0500 (EST)
Message-Id: <1425041044.54292.233221517.5204784B@webmail.messagingengine.com>
X-Sasl-Enc: kZxRh1vkULVlINncckmv2G+z7Ne08uv05OZC0dwJPM35 1425041044
From: andre76@fastmail.fm
To: Simon Nicolussi <sinic@sinic.name>
MIME-Version: 1.0
X-Mailer: MessagingEngine.com Webmail Interface - html
Date: Fri, 27 Feb 2015 13:44:04 +0100
In-Reply-To: <20150226165538.GA24850@blues.local.sinic.name>
References: <1424955764.2354591.232742237.2CF4B4C5@webmail.messagingengine.com>
 <20150226165538.GA24850@blues.local.sinic.name>
Cc: tor-talk@lists.torproject.org
Subject: Re: [tor-talk] Problems? Verifying signatures in Tor 4.0.4
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>



On Thu, Feb 26, 2015, at 05:55 PM, Simon Nicolussi wrote:
> andre76@fastmail.fm wrote:
> > $ gpg --verify tor-browser-linux32-4.0.4_en-US.tar.xz.asc                
> 
> Note that calling gpg --verify with a detached signature as its only
> argument is insecure (later versions of GnuPG should emit a warning).
> See my message to Gnupg-users and subsequent responses for details:
> http://lists.gnupg.org/pipermail/gnupg-users/2014-November/051333.html
> 

I could read those responses until the end of time and wouldn't
understand anything.

Could you tell me what I'm supposed to enter in Terminal to get a
response that indicates a good file or a bad file?

Here's what I entered (2 separate ways);

$ gpg --verify tor-browser-linux32-4.0.4_en-US.tar.xz.asc 
tor-browser-linux32-4.0.4_en-US.tar.xz.asc

gpg: Signature made Wed 25 Feb 2015 02:54:55 AM EST using RSA key ID
F65C2036
gpg: BAD signature from "Tor Browser Developers (signing key)
<torbrowser@torproject.org>"


$ gpg --verify tor-browser-linux32-4.0.4_en-US.tar.xz.asc 
tor-browser-linux32-4.0.4_en-US.tar.xz

gpg: Signature made Wed 25 Feb 2015 02:54:55 AM EST using RSA key ID
F65C2036
gpg: Good signature from "Tor Browser Developers (signing key)
<torbrowser@torproject.org>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the
owner.
Primary key fingerprint: EF6E 286D DA85 EA2A 4BA7  DE68 4E2C 6E87 9329
8290
     Subkey fingerprint: 5242 013F 02AF C851 B1C7  36B8 7017 ADCE F65C
     2036













> -- 
> Simon Nicolussi <sinic@sinic.name>
> http{s,}://{www.,}sinic.name/
> Email had 1 attachment:
> + Attachment2
>   1k (application/pgp-signature)

-- 
http://www.fastmail.com - A no graphics, no pop-ups email service

-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

