Jump to content

Sha256 File Signatures For Blesta Releases


interfasys

Recommended Posts

It would be great if file signatures could be posted somewhere so that we know we're getting the real thing. Nothing worse than leaks in a billing software.

Preferred format would be SHA256.

 

As long as you get the files from https://account.blesta.com you will be fine. Our customers can download them from our download manager if they wish but we download them from the url above and ours has to be https://licensecart.com/billing/

Link to comment
Share on other sites

If their system has been compromised, then you're done for. Files could have been modified through Blesta, FTP, PHP exploit, etc. and you wouldn't know.

It's just common practice to offer at least MD5 sigs.

 

Blesta own their own servers on their own racks in the datacenter next to the office (I believe) they aren't like WHM** who erm use HostGator :D and Blesta keeps up-to date on software and updates.

Link to comment
Share on other sites

Blesta own their own servers on their own racks in the datacenter next to the office (I believe) they aren't like WHM** who erm use HostGator :D and Blesta keeps up-to date on software and updates.

You can own as much hardware as you want, that doesn't make you invulnerable to security breaches no matter how good of a security plan you have in place.

Having the signatures can also help validate corrupt downloads/uploads of files.

Link to comment
Share on other sites

You can own as much hardware as you want, that doesn't make you invulnerable to security breaches no matter how good of a security plan you have in place.

Having the signatures can also help validate corrupt downloads/uploads of files.

 

1 in a million chance. and everything is encrypted when uploaded the file names are like 123450kiourejkwodgtpwe.zip

Link to comment
Share on other sites

1 in a million chance. and everything is encrypted when uploaded the file names are like 123450kiourejkwodgtpwe.zip

 

Not saying they don't have good security policies in place but being able to validate my download is useful for more then just tampering as I pointed out above. 

 

I don't trust any site 100% so the more ways I can verify things the better.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...