In the early days of Nxt, there was at least instance where someone modified the Nxt binaries to transmit the passphrase to their own website, uploaded the modified binaries to a download site, and persuaded some people to use this. At least 3-4 people lost their coins because of this.
As mega.co.nz links don't work for everyone (e.g. servers using curl/wget), direct download mirror links will be offered, and we need a way to verify these.
The Nxt team put in a couple of measures to stop this, which I think work well:
- Every download has a SHA256 hash
- Every important message from the developer (especially those which include a download URL) is signed
- The first post links to the signed post with the download link
Could you please do something similar?
There were four of us that lost Nxt as a result. I lost 147k Nxt. And it became the biggest distraction for Nxt for the next several weeks. Avoid the pain and the bad press - follow notsoshifty's suggestions, please.