pgp fingerprint comparator
mirror checkhere is the trust problem in one sentence: scammers publish lookalike keys. a mirror site copies everything - layout, texts, even the "verify our key" section - but swaps in their own public key. every signature you then verify against it passes, because it was made by them. the defense is simple: compare the key's fingerprint over two independent channels (e.g. the mirror on one side, the official announcement or keyserver on the other). if they don't match, walk away.
two ways this runs: with javascript enabled everything happens in your browser via openpgp.js - nothing is uploaded anywhere. with javascript blocked the form posts to our server instead, where the comparison runs once in memory and is never stored or logged - but the pasted keys do cross the network.
good to know
- what exactly is a fingerprint?
- it is a hash of the key packet that works as the key's unique id: 40 hex characters on classic v4/v5 keys (sha-1 based), 64 on newer v6 keys (sha-256 based). two keys with identical fingerprints are cryptographically the same key, no wiggle room.
- why would mirrors swap keys at all?
- because verification is only as good as the key you verify against. with their own key published on a fake mirror, scammers can sign whatever they want and it will "verify". swapping the key turns your own security ritual against you.
- armored key vs bare fingerprint?
- this tool accepts both, in any mix - public or private blocks alike. an armored key gets parsed and its real fingerprint computed - plus you get creation date and identity count as sanity signals. a bare fingerprint can only be compared literally: there is nothing to parse, so no validity check is possible. make sure you copied all characters.
- what should the "official source" be?
- a channel the scammer cannot edit: the project's clearnet site fetched directly, a signed announcement, a well-known keyserver - ideally more than one. never take both sides of the comparison from mirrors of the same network.
- does my key get uploaded?
- not when javascript is on: parsing and comparing happen inside your browser tab. when javascript is blocked, the form posts and the server computes both fingerprints in memory for that single request - nothing is logged, cached or stored - then discards everything. prefer the browser path whenever you can.