SSL certificates, gpg and others are great, but current ways to use public keys for encryption and signing lack something that could be helped with little bit of separate from internet communication.
SSL certificate's secret key, the part that has to be kept hidden, might have been stolen in secret. Or worse, the organization itself might be crooked and deliver altered files to some percentage of downloaders or specific downloaders.
First time delivery of a public key over the internet is vulnerable.
SSL certificates have expiration dates. And for good reason.
This is mostly for when installing an OS, like a Linux distro, from an ISO file, to be used for years. Or when taking public keys for use. Single home users usually would not use this monthly, but maybe once per year.
There would be monthly hash and key file for many different open source projects, published on many sites. Then on some worldwide physical magazine or newspaper printed on paper and sold in streets, on it's classified ad section, a small ad containing the sha256 or sha512 code, the master-hash for the hash and key file.
This would not replace anything, just be extra and in addition to existing methods.
Also, as a possible extra, a monthly ceremony of video reading of the master-hash by various people, even on the internet, would increase trust.
Users of the hash and key file could be: Top 100 Linux distros, FreeBSD, OpenBSD, firefox, google, bitcoin, litecoin and other cryptocurrencies, some big repository of public keys, microsoft, apple...
.
This is output from sha256sum, a program in every Linux distro. Is it in mac and windows too? Reading this out loud takes a minute:
964ee9592e219a93759a26909e38a0e49201c52d6779d4597ef1c3152c54fe36
submitted by [comments]
SOCIAL SHARE CARD GENERATOR