Release notes
- BitBox02: fix missing button to re-install firmware, fixing interrupted installs ("invalid firmware").
- Fix Wallet Connect issue where account unspecified by the connecting dapp caused a UI crash.
- Fix Wallet Connect issue with required/optionalNamespace and handling all possible namespace definitions.
- Fix BitBoxApp crash on GrapheneOS and other phones without Google Play Services when scanning QR codes.
Verifying the release
Get a public key of security@shiftcrypto.ch with fingerprint DD09 E413 0975 0EBF AE0D EF63 5092 49B0 68D2 15AE
:
curl https://bitbox.swiss/download/shiftcryptosec-509249B068D215AE.gpg.asc | gpg --import
Download the app for your platform and the corresponding .asc
file and place them in the same folder.
We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.
To verify the signature, execute:
gpg --verify BitBox-4.42.1-macOS.zip.asc
You should see the following output:
gpg --verify BitBox-4.42.1-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.42.1-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg: using RSA key DD09E41309750EBFAE0DEF63509249B068D215AE
gpg: Good signature from "ShiftCrypto Security <security@shiftcrypto.ch>" [ultimate]
(The [ultimate]
could say [unknown]
or something else depending on your trust level.)