....why isn't the xc releases signed with pgp and why download files don't have any checksums.
We need to be 100% careful, hackers are targeting all crypto.
Fully agree.
We should all urge devs on this as a top priority.
TAILS is a nice example how it can be handled
https://tails.boum.org/download/index.en.htmlRight (and rather simple) tools like PGP, SHA256 brings BIG results.
Hard to overvaluate them...
...Also xc official homepage isn't very friendly, the slide down buttons may be gimmicky but it is covering the other links ...
Right. But I can live with that. Not a deal breaker