Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run and show Virustotal scan results on download page #117

Open
ovz93br43v7 opened this issue Feb 16, 2021 · 2 comments
Open

Run and show Virustotal scan results on download page #117

ovz93br43v7 opened this issue Feb 16, 2021 · 2 comments
Labels
enhancement New feature or request index.html

Comments

@ovz93br43v7
Copy link

Creating a feature request

Thanks for this awesome project!

Is your feature request related to a problem? Please describe:

No direct problem, just general fear of infecting the home network. I am neither an IT expert nor a security expert, but I would feel safer in general if there was the possibility to verify the download with GPG to be sure that the image is from the original author.

Describe the solution you'd like:

I would like to have a way to verify the downloaded image. You already provide a SHA256 hash, but probably it is possible to extend this with a gpg signature check? (guide example see KeepassXC)
Additionally it would be nice to see the result of a Virustotal scan per image. Yes this could be donw by the user but probably you can automatically do this during the build process.

Describe alternatives you've considered:

Virustotal scan can be done by the user itself, he/she has only to wait (depending on upload speed).

Vote for this feature on FeatHub: https://feathub.com/MichaIng/DietPi/+215

@MichaIng
Copy link
Owner

MichaIng commented Feb 16, 2021

Many thanks for your suggestion.

It was asked already for having the hashes online and for the archive, instead of as part of the archive for the contained image. If I'm not wrong, checksums are part of the 7z archive format, checked by the unarchivers already, so the integrity of the contained image actually does not need to be checked.

So I like the idea of covering online integrity checks of the archive, before extracting it and adding authenticity via DietPi GPG signature. I need to dig into how to have this verified and added to known key servers, but we can show the signature on our download page for now.

I plan to create an own APT server as well (we already maintain a few DEB packages), so a DietPi GPG key is required anyway.

@MichaIng MichaIng transferred this issue from MichaIng/DietPi Jun 3, 2021
@MichaIng MichaIng added the enhancement New feature or request label Jun 3, 2021
@MichaIng MichaIng changed the title [Feature request] Add a way / guide to verify signature / downloads and scan result of Virustotal Run and show Virustotal scan results on download page Jun 3, 2021
@MichaIng
Copy link
Owner

MichaIng commented Jun 3, 2021

I transferred the issue to the website repository, where it fits better, and focused it on the automated AV scan. The other request to add download signatures is tracked here: #118

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request index.html
Projects
None yet
Development

No branches or pull requests

2 participants