oxedyne/daimond/verify/ext/README.md
1.9 KiB, 1 run
created by r2519314175:1007, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | # Daimond Verify (browser extension) |
| 2 | |
| 3 | The trustworthy, always-on form of "check the code your browser is running". |
| 4 | |
| 5 | The in-page check at `/verify.html` is convenient but weak: a tampered server |
| 6 | could serve a tampered checker. This extension cannot be tampered with that way, |
| 7 | because **it is installed from source, not served by the site**. On every load |
| 8 | of a Daimond origin it re-checks the served build against the site's own bytes |
| 9 | and the transparency log on GitHub — an origin the site does not control — and |
| 10 | colours the toolbar badge: |
| 11 | |
| 12 | - **✓ green** — the code just loaded is the published source, and that build is a |
| 13 | sealed entry in the public log. |
| 14 | - **✗ red** — it is not. Something is wrong; do not enter anything sensitive. |
| 15 | - **? amber** — could not be sure (usually offline, so the public log was |
| 16 | unreachable). |
| 17 | |
| 18 | Click the badge for the detail: which checks passed, the build id, the bundle |
| 19 | hash. |
| 20 | |
| 21 | ## What it checks |
| 22 | |
| 23 | Exactly what `verify/check.mjs` checks, with the same algorithm |
| 24 | (`fingerprint.js` is a deliberate copy of `verify/lib.mjs`, and |
| 25 | `verify/verify.test.mjs` asserts they agree): |
| 26 | |
| 27 | 1. the served `manifest.json` is internally consistent; |
| 28 | 2. its bundle hash is a **sealed entry in the public transparency chain** — the |
| 29 | check that counts, made against GitHub; |
| 30 | 3. every file the site served hashes to what the manifest says. |
| 31 | |
| 32 | ## Install (unpacked) |
| 33 | |
| 34 | Chromium: `chrome://extensions` → Developer mode → *Load unpacked* → this |
| 35 | directory. It vouches for `daimond.oxedyne.com` (and `localhost:8777` for local |
| 36 | development) and nothing else, so the badge stays meaningful. |
| 37 | |
| 38 | The public transparency log defaults to |
| 39 | `raw.githubusercontent.com/oxedyne-com/daimond/main/verify/transparency.jsonl`. |
| 40 | Set `chrome.storage.local` `logUrl` to point a fork or mirror at its own. |
| 41 | |
| 42 | ## Status |
| 43 | |
| 44 | Dev/unpacked. A published build would pin a `key` (a stable id) and ship through |
| 45 | the browsers' stores; the checking logic is complete and tested |
| 46 | (`dev/verify_ext.mjs`). |