It takes a couple of minutes, and it tells you the file you got is exactly the one we published, not something swapped in along the way.
Every release is signed with this key. Its fingerprint is what identifies it: compare it with the one your tools show.
| Name | Biscuit Wallet releases |
|---|---|
| Type | RSA 4096 |
| Fingerprint | D714 332E 6101 C1DA AC60 E644 202F 1FA3 98DE CEFA |
The public key is on the download page, in SECURITY.md, and built into Biscuit: the app installs an update only after checking this signature.
Each release has a list of SHA-256 checksums, hashes-<version>-plain.txt, signed with the key above. With GnuPG installed (on a Mac, from GPG Suite or Homebrew; on Windows, Gpg4win):
gpg --import biscuit-release-key.asc
gpg --verify hashes-1.0.9-plain.txt
The output must say Good signature from “Biscuit Wallet releases”, and the fingerprint must match the one above. GnuPG may add that the key is not certified with a trusted signature: that only means you haven’t signed our key yourself.
Compute the checksum of the file you downloaded and find the same value, next to the same file name, in the signed list.
| macOS | shasum -a 256 biscuit-1.0.9-mac-arm64.zip |
|---|---|
| Linux | sha256sum biscuit-1.0.9-linux-appimage.zip |
| Windows | certutil -hashfile biscuit-1.0.9-win.zip SHA256 |
If the values differ, don’t open the file: download it again from biscuitwallet.com.
Releases are built with Guix, so you can also rebuild one yourself and compare: see Reproducible builds.