This guide walks through verifying that a downloaded Superbacked release has not been tampered with using SHA256 checksums and PGP signatures.
SHA256SUMS and SHA256SUMS.ascDownload SHA256SUMS and SHA256SUMS.asc from the release page to the same folder as the app.
SHA256SUMS using GnuPGHeads-up: integrity of Sun’s PGP public key can be confirmed using fingerprint published on sunknudsen.com/contact, GitHub, Twitter and YouTube.
Heads-up: “1 signature not checked due to a missing key” warning can be ignored as it refers to Sun’s legacy PGP public key.
Import Sun’s PGP public key and verify the signature.
Verify the output shows Good signature from "Sun Knudsen <hello@sunknudsen.com>" and the primary key fingerprint matches E786 274B C92B 47C2 3C1C F44B 8C9C A674 C47C A060.
Verify the output shows OK for the downloaded release.
Copyright (c) Superbacked, Inc.