logoalt Hacker News

maccardyesterday at 3:27 PM2 repliesview on HN

Which is served from the same insecure domain. If the download is compromised you should assume the hash from here is too.


Replies

hypeateiyesterday at 3:30 PM

An integrity check is better than nothing, but yes it says nothing about its authenticity.

show 3 replies
firesteelrainyesterday at 3:46 PM

There is a secure domain to download from as a mirror. For extra high security, the hash should be delivered OOB like on a mailing list but it isn’t

show 1 reply