GOSSIP USERS - SECURITY ALERT: There is no 0.5.3 release of gossip. If you installed a package with version 0.5.3, you might have just been hacked by someone. The official releases are on github and nowhere else. I will follow up this alert (by replying to it) with additional information as it becomes available.

NOTE: If you compiled from source and the version says 0.5.3-unstable, this is fine. That is not a 0.5.3 release, that is the tag for commits in-between release 0.5.2 and 0.5.3. Compiled code is always much safer than a package.

Reply to this note

Please Login to reply.

Discussion

SHA256 sums of everything released and then some (signed in this event by my nostr key)

a03207e4f357dc71e474b7cee6348031e5e3486c319a39f026b867ac50d29915 0.4.0/gossip_0.4.0_amd64.deb

5ee124a9bb377d0048eb32312d6529e6187548d76fce2572aef3c5c0c9653ddc 0.4.0/gossip-0.4.0-debian.zip

5619e84a3e7e8420945b522a5f406d06a52e1642e5c944b236bf674f45e64ce8 0.4.0/gossip-0.4.0-microsoft-windows.zip

30ea3089e1c01341aeab703d41b335c12f3a906b120ee543f7af35f2602ab0d0 0.4.0/gossip.0.4.0.msi

02cd6bd850753a324349bb2918c4b66488126e04c12a7dc1b9ed57a9908e9c40 0.4.0/mikedilger.pgp.txt

1d1f983a25c3edd24f91fc77475b37425d5d0ba8a6dba94a14b2322e1a5b4f6a 0.4.0/SHA256SUMS.txt

4815ce53708600ef609882c4d7356d13296959dcd5f77c33040abb444e111d1c 0.4.0/SHA256SUMS.txt.sig

5874dfb38a734d792fbd3a222bb7e63ad2dda2cd88a067aa2f208e91eb45b626 0.5.0/gossip_0.5.0_amd64.deb

0fae567434dfe12cfbe025e521ab37d2524d04df4a2d27369e6ef00ec9f01445 0.5.0/gossip_0.5.0-cjk_amd64.deb

ad1fbbb0883bd9c907695ab3c591a4a17a91288d513570e6e6bcdd9eea46b573 0.5.0/gossip.0.5.0-cjk.msi

67ab4d1eb8f520f752e0dcb3c3e9eeeacce8ffec65d90b157fe08cfe940c635b 0.5.0/gossip.0.5.0.msi

a0353350087e9e2ebd5b94e8230a4b584667bc6d76aa8791d4c7b235c108b87f 0.5.1/gossip_0.5.1_amd64.deb

22640bb52d4cb926123397c4025ca7fab64d51b5157efb133ffdad19cba7f06d 0.5.1/gossip.0.5.1-cjk.msi

d556276d19b7fcd3f07c4eadd0e712f7f737ff5168591fdeb7a9dd0504874c1c 0.5.1/gossip.0.5.1.msi

eb04388d79136606da915b429d63c0b9af961b8c2f194bb2492db64a7e0ae047 0.5.2/gossip_0.5.2_amd64.deb

e8d71b3d1849c856729913fe949bdc0bfb40c2f1a034e96a77adb44e233562b6 0.5.2/gossip_0.5.2-cjk_amd64.deb

8a0ab311ccf814bc8e7c00f29fc5ab77f36583659b244fe0bdb2c334ddd103a4 0.5.2/gossip.0.5.2-cjk.msi

35aa28e8a9599805419bfa50579579216a9495f2bbc66383b43a0deb6eea6040 0.5.2/gossip.0.5.2.msi

I have the 0.5.2/gossip.0.5.2.msi

I don't think it's a virus, I think the build config is putting 0.5.3 in there when it's really 0.5.2. I didn't get updated but Windows thinks there's a virus in here, for some reason, when I don't think there is, given the SHA 256 checks out. It's the installer you produced.

the 256-SHA hash is correct but it says this:

Subject: Gossip 0.5.3 Installer

OMG You are right.

The real issue, for me, is that Microsoft Defender is producing a false positive for

Trojan:Script/Wacatac.H!ml

I should just build from source, I guess. I'm lazy.

I have this…

Compiling gossip v0.6.0-unstable

compiling from source…should be fine I am guessing.

Check #[5]

False alarm and entirely my fault. I put the wrong version number into the windows package for 0.5.2.

To avoid confusion, there will be no 0.5.3 release, I will skip to 0.5.4 if that branch gets another patch.

#[1]