Software Signature Verification Usability Issues and Proposed Solutions

Severe Usability Issues with Software Signature Verification such as GnuPG and Proposed Solutions / Secure Downloader Development Notes
Contents
Problem[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Problem
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Problem|Problem]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Problem](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Problem)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Problem](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Problem)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Problem]Problem[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Quote Warning page, Always Verify Signatures:
For greater system security, it is strongly recommended to avoid installing unsigned software. Always make sure that signing keys and signatures are correct and/or use mechanisms that heavily simplify and automate this process, like apt upgrades.
As a reminder, digital signatures are not a magic bullet. While they increase the certainty that no backdoor was introduced by a third party during transit, this does not mean the software is absolutely "backdoor-free". Learn more about this process and what digital signatures prove.
Surveys ([Dev/Download_Statistics example]) have shown that very few users use software signature verification. Even fewer users have a sufficient understanding of the threat model. In case of an attack by an advanced adversary most users would get compromised. This is the very strong opinion of the author of this text. Usually the author of this text seldom raises strong opinions.
Required knowledge is far too much. Usability of tools used for manual verification of software signatures is such as GnuPG is far too bad. For an elaboration of these issues, see Conceptual Challenges in Software Digital Signatures Verification and Verifying Software Signatures.
Solutions[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Solutions
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Solutions|Solutions]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Solutions](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Solutions)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Solutions](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Solutions)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Solutions]Solutions[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Metalink[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Metalink
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Metalink|Metalink]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Metalink](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Metalink)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Metalink](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Metalink)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Metalink]Metalink[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Metalink are links which support additional metadata. Such as in theory links to signing keys, software signatures. Browser could implement support for metalink and automation of software verification.
Would require Metalink including OpenPGP support.
GSoC may be way to get this feature into Firefox.
- https://en.wikipedia.org/wiki/Metalink
- https://bugzilla.mozilla.org/show_bug.cgi?id=331979
- https://web.archive.org/web/20201214130913/https://github.com/Whonix/Whonix/issues/21
Metalink would only be a gradual improvement. Download security is harder than just verification of software signatures. Rollback (downgrade), indefinite freeze attacks and other attacks would still be possible. See TUF Threat Model, TUF: Attacks and Weaknesses for further information.
https://daniel.haxx.se/blog/2021/06/07/bye-bye-metalink-in-curl/
Subresource Integrity[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Subresource_Integrity
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Subresource_Integrity|Subresource Integrity]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Subresource Integrity](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Subresource_Integrity)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Subresource Integrity](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Subresource_Integrity)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Subresource_Integrity]Subresource Integrity[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Would solve mirror issue.
Unavailable for file downloads.
https://github.com/w3c/webappsec-subresource-integrity/issues/68
OpenPGP Signed Website[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#OpenPGP_Signed_Website
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#OpenPGP_Signed_Website|OpenPGP Signed Website]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[OpenPGP Signed Website](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#OpenPGP_Signed_Website)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[OpenPGP Signed Website](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#OpenPGP_Signed_Website)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#OpenPGP_Signed_Website]OpenPGP Signed Website[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
OpenPGP Signed Websites and browsers verifying website signatures do not exist yet either.
Key Distribution[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Key_Distribution
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Key_Distribution|Key Distribution]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Key Distribution](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Key_Distribution)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Key Distribution](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Key_Distribution)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Key_Distribution]Key Distribution[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Even if browsers (such as Firefox, Chrome) and/or downloaders (such as wget, curl, aria2c) had support for metalink and OpenPGP verification there would still be no concept on how to distribute the signing keys. This is a hard problem. TLS has the same issue. The certificate authority (CA) system problem.
DANE (DNS-based Authentication of Named Entities) might be a way put the root anchor into the DNS but that's no perfect end-to-end authentication either.
Deprecated Ideas[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Deprecated_Ideas
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Deprecated_Ideas|Deprecated Ideas]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Deprecated Ideas](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Deprecated_Ideas)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Deprecated Ideas](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Deprecated_Ideas)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Deprecated_Ideas]Deprecated Ideas[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
JavaScript Based Verification[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#JavaScript_Based_Verification
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#JavaScript_Based_Verification|JavaScript Based Verification]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[JavaScript Based Verification](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#JavaScript_Based_Verification)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[JavaScript Based Verification](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#JavaScript_Based_Verification)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#JavaScript_Based_Verification]JavaScript Based Verification[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Threat model:
- A) When avoiding mirrors: No JavaScript (JS) based verification is required because both download and JS come from the same source with the same trust level.
- B) If using mirrors: JS based verification can make sense but gpg bases is much more secure.
Usability considerations:
- Lack of automation: Cannot be automated. The user manually using the verification button is always required.
- StreamSaver.js feature request: check integrity of downloaded files
- StreamSaver.js feature request: check integrity of downloaded files
Security considerations:
- JS dependency: Conflicts with noJS users. Impossible to implement without JS.
Development effort considerations:
- High effort: Lots of effort to then be ignored by noJS users.
SecureDownloader[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#SecureDownloader
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#SecureDownloader|SecureDownloader]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[SecureDownloader](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#SecureDownloader)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[SecureDownloader](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#SecureDownloader)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#SecureDownloader]SecureDownloader[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Introduction[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Introduction
Click below ↴ = Copy to Clipboard
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Introduction|Introduction]]
Copy as Wikitext
[Introduction](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Introduction)
for Discourse, reddit, GitHub
[Introduction](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Introduction)
Copy as Markdown
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Introduction]Introduction[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Deprecated idea.
Stub downloader. Similar to the one that Mozilla is providing for Firefox downloads. A small tool that is used to download and install the real tool.
Securing downloads may be better when written as a general purpose tool (not specific to Kicksecure).
No other projects such as Firefox or Debian support this use case.
Open Questions[edit]
Copy or share this direct link!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Open_Questions
Click below ↴ = Copy to Clipboard
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Open_Questions|Open Questions]]
Copy as Wikitext
[Open Questions](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Open_Questions)
for Discourse, reddit, GitHub
[Open Questions](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Open_Questions)
Copy as Markdown
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Open_Questions]Open Questions[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- How to download and verify the host program in the first place?
- Without being able to answer this question the thing becomes a circle and doesn't actually solve anything.
- How to download the secure downloader itself in censored countries?
- How to download files in censored countries?
- Torify downloads?
Challanges[edit]
Copy or share this direct link!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Challanges
Click below ↴ = Copy to Clipboard
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Challanges|Challanges]]
Copy as Wikitext
[Challanges](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Challanges)
for Discourse, reddit, GitHub
[Challanges](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Challanges)
Copy as Markdown
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Challanges]Challanges[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Such a host program is host operating system specific, well you can write it in a cross platform language but still have to struggle with platform specific quirks.
The Tor Project never managed to get such a downloader up and running, see Thandy.
Conclusion[edit]
Copy or share this direct link!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Conclusion
Click below ↴ = Copy to Clipboard
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Conclusion|Conclusion]]
Copy as Wikitext
[Conclusion](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Conclusion)
for Discourse, reddit, GitHub
[Conclusion](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Conclusion)
Copy as Markdown
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Conclusion]Conclusion[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Not useful. Better to fix the root issue upstream.
Resources[edit]
Copy or share this direct link!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Resources
Click below ↴ = Copy to Clipboard
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Resources|Resources]]
Copy as Wikitext
[Resources](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Resources)
for Discourse, reddit, GitHub
[Resources](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Resources)
Copy as Markdown
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Resources]Resources[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- liberationtech: secure download tool - doesn't exist?!?
- proposal to defend a permanent takedown threat
TUF (The Update Framework)
[1]- TUF Threat Model,
TUF: Attacks and Weaknesses
[2] - GPG signatures do not authenticate filenames
- https://gitlab.torproject.org/legacy/trac/-/issues/2340#comment:14
- Metalink
- update checking requirements discussion for bitcoin-qt by Bitcoin developer
- https://sourceforge.net/p/aria2/feature-requests/221/
See Also[edit]
Copy or share this direct link!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#See_Also
Click below ↴ = Copy to Clipboard
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#See_Also|See Also]]
Copy as Wikitext
[See Also](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#See_Also)
for Discourse, reddit, GitHub
[See Also](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#See_Also)
Copy as Markdown
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#See_Also]See Also[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- Verifying Software Signatures
- OpenPGP
- Verify the images
- Kicksecure Signing Key
- Software Signature Verification Usability Issues and Proposed Solutions
- OpenPGP Signed Websites
Footnotes[edit]
Copy or share this direct link!
https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Footnotes
Click below ↴ = Copy to Clipboard
[[Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Footnotes|Footnotes]]
Copy as Wikitext
[Footnotes](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Footnotes)
for Discourse, reddit, GitHub
[Footnotes](https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Footnotes)
Copy as Markdown
[url=https://www.kicksecure.com/wiki/Software_Signature_Verification_Usability_Issues_and_Proposed_Solutions#Footnotes]Footnotes[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.


Copy as Wikitext

for Discourse, reddit, GitHub

Copy as Markdown

Copy as phpBB Click below ↴ = Open social URL with share data











We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!