Comments (5)
If it helps, the MD5/SHA1 checksums for the current distribution files are available here:
https://exiftool.org/checksums.txt
from exiftool.
Hi Phil, Thanks for getting back to me so quickly. Checksums are brilliant for error detection but less good for security. If the site was compromised then as well as switching the application file, an attacker would also alter the checksum values so that they matched.
(One of) The good thing about PGP is that if you have signed something then it is impossible to repudiate that it was signed by anyone other than your private key. If you keep your private key on a fairly secure offline machine then the risk of compromise is pretty low.
from exiftool.
Thanks for the explanation. I did a quick bit of research. It looks simple enough to create a detached signature with gpg. I'll consider adding this to the release scripts.
- Phil
from exiftool.
Cheers Phil 👍 :) . I'm on Mac and I use GPG Keychain which is super easy to use, and I would highly recommend.
from exiftool.
I'll keep this open as a reminder until I get a chance to spend a bit of time on this.
from exiftool.
Related Issues (20)
- Exiftool adds non-mandatory YCbCrPositioning tag HOT 8
- Move code to GitLab or Codeberg HOT 3
- Error When Copying Metadata to JXL HOT 2
- Possible FujiFilm RAF tag decoding HOT 2
- Documentation issue on "LimitLongValues" HOT 15
- Artistic License Version HOT 1
- Error accessing MIE files in version 12.74 HOT 3
- JSON detected as wrong type if array containing object is MIMEtype HOT 1
- Missing TIFF-EPStandardID interpretation HOT 2
- Clarify JXL read/write support HOT 2
- "-*=" conflicting with "PNG-pHYs" tags HOT 7
- Encode mp3 tags in UTF8 HOT 9
- Microsoft Xtra tags - expand writable tags HOT 16
- Unable to update MAKE tag using exiftool 12.76 HOT 3
- consider a default behavior of reading mkv tags after the first cluster if indexed in the seekhead HOT 3
- Problematic handling of non-ASCII filenames on Windows HOT 21
- New Samsung GCamera XMP tags HOT 9
- [Suggestion] Report more modern variant of TTF MIME type?
- [Suggestion] New way of representing Palette in human-readable format HOT 2
- Firmware Versions, Canon 7D (or - strangeness recovering certain data) HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from exiftool.