Authenticate the signing key through the OpenPGP Web of Trust
Note that since all Tails releases are signed with the same key, you will not
have to verify the key every time and the trust you might progressively build in
it will be built once and for all. Still, you will have to check the ISO image
every time you download a new one!
If you want to be extra cautious and really authenticate Tails signing key in a
stronger way than what standard HTTPS offers you, you will need to use the
OpenPGP Web of Trust.
The verification techniques presented until now ([[Firefox extension,
BitTorrent|download/install]], or OpenPGP verification) all rely on some
information being securely downloaded using HTTPS from our website:
- The *checksum* for the Firefox extension
- The *Torrent file* for BitTorrent
- The *Tails signing key* for the OpenPGP verification
But, while doing so, you could download malicious information if our
website is compromised or if you are victim of a [[man-in-the-middle
The OpenPGP verification allows you to verify the ISO image even better
by also authenticating the Tails signing key through the OpenPGP Web of
Trust, without having to trust your download.
