This archive is built to be copied, mirrored, and re-shared — that's how it survives. But copies can be tampered with. Here's how to confirm that any file, torrent, or mirror you find is the genuine, unmodified archive.
Fetch the key and confirm its fingerprint matches the one above. Run this in your terminal:
Every release ships a SHA256SUMS file and a detached signature. This confirms the list came from us, unmodified.
✓ You want the line “Good signature from Archive Genocide”. A warning that the key is “not certified with a trusted signature” is normal for any downloaded signature — it just means you haven't personally marked our key as trusted. What matters is that the fingerprint matches the one above.
Run this in the folder you downloaded — from our torrent or from any mirror. Every file is confirmed byte-for-byte, and any missing or altered file is flagged.
The archive ships as two media volumes. The verification is identical for Volume 2 — just use
its filenames: gpg --verify SHA256SUMS-torrent2.asc SHA256SUMS-torrent2, then
sha256sum -c SHA256SUMS-torrent2. Same signing key, same process.
A signature proves that content is authentically ours — it does not prove that a website is us. Anyone can clone this site and even copy our key and signatures onto it. A page looking right, or a file verifying, does not make the operator trustworthy.
So: read mirrors freely, and confirm their files with the steps above. But treat the page itself as untrusted unless it's on one of our official domains listed above (archivegenocide.com, .org, or .is — or a new address we announce on Telegram/Twitter if those ever change) — especially for anything that asks you to upload, log in, or submit.