How to verify a legit download of Daedalus for beginners

Here is the video. Not sure if this should go in the Education forum or the Beginners forum.

Cheers!
Rick

3 Likes

Great job @rickymac!

2 Likes

If someone spoofed or hacked the website, wouldn’t they be able to replace the SHA256 strings just as easily as the installer itself? :thinking: So, verifying the checksum at best gives you a chance of detecting unsophisticated attacks and at worst a false sense of security.

PGP signature is where it’s at, you can save IOHK’s signing key on your computer now and verify each future Daedalus release using this key later. The verification process is as easy as right clicking the Daedalus installer, then selecting PGP verification from the context menu.

Also there are multiple ways to obtain and verify IOHK’s public key:

  • Detailed instructions on the Daedalus website.
  • Look up signing.authority@iohk.io on the SKS Keyserver Pool using your PGP software.
  • Here’s the key signature on @IOHK_Charles Twitter.
  • You can even post the key on this forum, the fingerprint is D325 87D4 090F E461 CAEE 0FF4 966E 5CB9 CBFA A9BA:
IOHK Signing Authority public key
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: SKS 1.1.6
Comment: Hostname: pgp.mit.edu

mQINBFsMKfIBEADZyjIyq9IUMKEK/WoRI55yuezgbsp84lVUN24vCvnVTHoZwRrTSvL6bGMn
6XSz6pOEHl+pcHkE2Ur3D+3UV9HPIP8BiPyyThKxI+lOgF4//5SIU5zZRhfD/1GjN/G4Q4EG
4BGivVP44c4q9WIO//P2TN48kZin0FYgrnAFdJAoLfPUs3I5WKVtO70yhWq70NBXHepuDQ/F
dKrJWephvZWlfHcf5EGfeCd7/FORBQYEVA6hzXjduib0QwLoHtcNqsRs+HDNZTEKl5j1ql7s
CJWOuzm7QtkW0DWvlzUnepT+ecqXkINOM1Unrj5lrXIxuKB0mf+MGUS3b7oxPrSx7Cy+32Py
QGCXQGLsRz7GEMqYTY1cNznMA975l7hdCpZgvZ/guH3F245aUBzuiPrXFPbWpAiEd7veZB8S
spegxLG4mxJmPHiByFyzsZoNGgN6SflvjxKSgwR+Kiu1XlI42LM2IOsiAhHX5cm1jCv4DQLW
jw0L7sDXAM4sHeCNPwapd8L5RuinDyl0P8XPu9c8fkZHjF8gitmNyNTWLfvzsDuENFyNzLVb
5ztsgCM+QP89zCKd/v7ncafpaVuCINRWcrW/iL40vm6bZ6rMKqqEiIFz97VqoUZIAnmFpFVy
CrmGsyMxT8zVpLDHZtQs+sAq9iqtIH5WZbkkRgacTMgGvqr+tQARAQABtDJJT0hLIFNpZ25p
bmcgQXV0aG9yaXR5IDxzaWduaW5nLmF1dGhvcml0eUBpb2hrLmlvPokCVAQTAQgAPhYhBNMl
h9QJD+Rhyu4P9JZuXLnL+qm6BQJbDCnyAhsDBQkJZgGABQsJCAcCBhUICQoLAgQWAgMBAh4B
AheAAAoJEJZuXLnL+qm67RwP/0R5TEumANL5QdLiF2ehz7pSWAjT77Z7pNwe2jtQXSmaoR7X
f8bcnh4Nb5nnW+UsMFOX3DN3Dzf/f0CuWlTlf7INs7Mhgd1n2TOsGVFw/RUbReVfjruj+OG/
m/eLGcUWsr+GwoLoM+NPbzogV/p5jCQb8iiL6am9UR+zyqZcH7LXO4C9OQal3Mb4yEt4hmSy
5A4jAAKKpLokFnj97/f/NCjDiAY5A/tX5xDouxLByI664LTlvKIPd26IIw9IDDpFhnKpMgSN
SU7vWsz+HaJjInr2b0COSXxcZuk3Mo7DZP7Vw6viAHzteTNOMrXhoysqRY45ew/3hcRv2qdJ
hjtW/C1Ni9R1jL+AR+z8jIsKuNnMExdUTX3y+Fh0DN+2b37apJ2zNa7E38fznWg2WICdc9SU
p1W9XpZbHQ0ioMF0PGHAhBDc6WZyZplXsE9DoU91bv5qCOktSkSgwjirfJc4fYcdoeD96t/C
HOpVI3xifnuEi9J1KEpvdraB/yA+a0t0H/Gxa0fzCXrlbHifnzAS+g12ETt0onulydVEj/P2
VSgG/ZCa0Ru7p66NKLmkZVfuDZAgaJxdPkWQCWTeF+jtZgH3qIMWLvQVwB41lDNUU9eKb/5E
O6x83W7dDBpp1s4yvrgaoIZA5zxDcMS8Ri5W1IAu9HveWxFZk1cu2qMoShPruQINBFsMK1AB
EADXwGwjdXk12/BXWEtH+QVOSZfW00XHLnn1gfYWYGtRjtw/2z/tGf9ehPnGmGdNoWdGGxGk
jIj8f3M8YD1Qe+XWlILx9LSfTYL0gVnK7PgUJglcrRjbUgn6lvdZK32QlPA9/aHh+q4O7KKi
X4cJISPDVktWjuHIYI35SpLs0e4QoRGmmZiUw9g/NAVFFHT70nG27PHKqbmZSk4JAE9S4MC/
RaUwDc6zXN3O4M/JVC71nDv2v079m8cs8QefEtIjlKZmzesjzwkt99Alk6/gG+Cthy1Hb53W
rWdNlMEozFOF68sQroq7jP6FHMQEMmxiXYjXMzsvq7aPUjJ/5PxI+w2OXON5eVhsG/dxlr50
n7G4i5Grda7Hrak2260A01JZqwPbLRdkYwdgbyxeU4AFjOhJR2OxM6ICNQi/jGHTUOHFRtU/
UYSq7Mp/XV2jEX+FFnKSj2oADEyarxFonFiGF59F+7YmTWKXp3drgx3DoHb+7Xtv/cFvxaLR
M2bJtz3KV9Iflg1HvzEjEXZnv+qQwjbFBuiZ12vEkxq9XDUCT4glePUF+xbm65T13dulTwZm
IUtZ0bX2/CNrvv+WALEAv+lgo3++vvOcMj9oY+qvTHNYemuRfBw4wfTvBoRBvtB3hLWJn/d0
BCsaZ6cThMHOTVxU15UZ0NGYz1WvpYt6pZSapQARAQABiQRyBBgBCAAmFiEE0yWH1AkP5GHK
7g/0lm5cucv6qboFAlsMK1ACGwIFCQlmAYACQAkQlm5cucv6qbrBdCAEGQEIAB0WIQSfmEC1
CuU5onMs9kbBMVV/FHGUGgUCWwwrUAAKCRDBMVV/FHGUGjgFD/4/cOXf7/yJi5V870hqzmn2
wq482nNGkrQK+L7CLHKYLs9H+aD3xEVadLhmleCYQib/FjX6/W4H1rfIjSlIKwYeAwoyW3Aj
vkoTpnZVdADdCqtrgLPJ7mWMo5K13Qq/7Xb6ZS/4PFiVsIg+kBroSA11QBmfJuZhsV66Yn+p
66jJnf/XKrIMe85iiWg5+B1cEVvU22wcOcV14r8QZlXKim49YMb6TEXIXgIRR91JEKbsIAZa
+yH8vx80BoV6qx0MUmfU65hoiyJlubmzMlvHA5bnQZzUpdQLlEeeXtRA4iM/VgMkNt5In45t
bs24FtRf/Un23MveuMf7Q7lQwztlHAuzHW5WGf1SGVnibCM1XOfN/F/DNYINtRTdSzRdDTHv
qfyZTwyqH1IxH/A+vTDhLLlu3YEKsXHMwSj+70G1QVNatYxb3QX6tpVItI2LRlyJWlY9ZDW1
RsldLsYjiadWKeiMhW2C3fMA/GqpHg3UiMqEp/NPg0SfYnAS2ClmBZnwsyXrPW6HDGwjtamy
OwHdiVoRxel/iLyqFTHAY6uTDd6itzYhbUff+PgerbsmkQeAdkEe9SF/jXocV/1bxYPiuhK9
cy6Etf86Hd9tY24R40nU0xolkWhiGzYEjJw+M+y9v5YuMpTgtgP9hAXAILVHg3fKFLRPXmh6
WB7cpdhoh9qH5/9KD/4xkeP+VsUk8jN4WFKh/mDYcuXIrrRYn4H7VAUW7FRDq4Vwvr9TGuE7
/DxJTxm+lHWMFNyFGhum6ekUSn/szqnqg/2ZeNOifBGDJvqCJxf7oZSPRuZv62jCxqGV4UxI
3MeE2ypFUkFGOCfIb5JFRvUHjEgbUVsfywePLEBIVyeA1SKIkhzUlpF8KGzvakZqOyD4P31B
d5WWe/CoksNEfrCs+ACv4TLaEaizPFaG45yCtZMrgopWeZUhxXii3HpQIyeRG2Xmx4FPAKak
HLC9/C70zeRIQSdH15eVHUgQ6sMYbx3ik0wXrGsJOGR4PcI3moGcEpjB8SDnx0Rjdv/J2XAK
JEIdETvhvxas3Pb7sybo4/3AanbCc2BTuYO+6avaZoqI0c/ClJLDU5MQcM9sHRahg1FLgeBd
MZOYtpqnFa7FKNcQIoVixCSyTupM6V7rd5YSqF1dlEwgTvw/jcYV0MB50eqcWG2FMZRtSrEF
jSrMRWVG6b3bdgA/hZiISMIqFxHdbRnnSC81R57bcK7C7WIDqCXrQpK39Rl2D4Ahou1PMS2F
0no8oChIc5+7Ojz2J3oUveYoHT2GHpKfI8yaWdvZ4iCbVpgk7k9WyLX6Y7OCVazFYrMIDPfC
RTVKA0f26rOOwbOkyQ/XkPk6J4Vlx1om+hBnRHPWK+BiUa2i6a/jhQ==
=fpQp
-----END PGP PUBLIC KEY BLOCK-----
6 Likes

Holy cow, great insight @hayamoto_jr. I was planning on working out a PGP video using the instructions provided on the daedaluswallet_dot_io web page.

If it’s OK with you, I would like to make a video using the link in your “easy” method? The install and then right click -> verify is perfect. Since you are the originator of the “easy way” as far as I am concerned, I would like to test, try different software on Mac and Windows, and make the video - and give you credit in the video for the idea. Unless you already plan on making one.

No need to mention me, would only distract from the video. :slightly_smiling_face: I’m not planning on doing any videos myself.

1 Like