diff --git a/_includes/warning.html b/_includes/warning.html new file mode 100644 index 00000000..60892ded --- /dev/null +++ b/_includes/warning.html @@ -0,0 +1,7 @@ +
+ +
+

Warning: The binaries listed on this page were compromised for a short time. Users are suggested to take action. Please click here for details.

+
+ + diff --git a/_layouts/base.html b/_layouts/base.html index da72e2fb..961da791 100644 --- a/_layouts/base.html +++ b/_layouts/base.html @@ -4,6 +4,7 @@ {% include head.html %} + {% include warning.html %}
{% include header.html %} {{content}} diff --git a/_posts/2019-11-19-warning-compromised-binaries.md b/_posts/2019-11-19-warning-compromised-binaries.md new file mode 100644 index 00000000..42e0e542 --- /dev/null +++ b/_posts/2019-11-19-warning-compromised-binaries.md @@ -0,0 +1,17 @@ +--- +layout: post +title: "Warning: The binaries of the CLI wallet were compromised for a short time" +summary: The binaries available on this website were compromised for a short time +tags: [announcements] +author: ErCiccione +--- + +Yesterday [a GitHub issue about mismatching hashes coming from this website](https://github.com/monero-project/monero/issues/6151) was opened. A quick investigation found that the binaries of the CLI wallet had been compromised and a malicious version was being served. The problem was immediately fixed, which means the compromised files were online for a very short amount of time. The binaries are now served from another, safe, source. [See the reddit post by core team member binaryfate](https://www.reddit.com/r/Monero/comments/dyfozs/security_warning_cli_binaries_available_on/). + +It's strongly recommended to anyone who downloaded the CLI wallet from this website between Monday 18th 2:30 AM UTC and 4:30 PM UTC, to check the hashes of their binaries. If they don't match the official ones, delete the files and download them again. Do not run the compromised binaries for any reason. + +We have two guides available to help users check the authenticity of their binaries: Verify binaries on Windows (beginner) and Verify binaries on Linux, Mac, or Windows command line (advanced). Signed hashes can be found here: https://getmonero.org/downloads/hashes.txt. + +The situation is being investigated and updates will be provided soon. + +The Monero community