logoalt Hacker News

hypeateiyesterday at 3:30 PM3 repliesview on HN

An integrity check is better than nothing, but yes it says nothing about its authenticity.


Replies

firesteelrainyesterday at 3:40 PM

You can use this site

https://distro.ibiblio.org/tinycorelinux/downloads.html

And all the files are here

https://distro.ibiblio.org/tinycorelinux/16.x/x86/release/

Under a HTTPS connection. I am not at a terminal to check the cert with OpenSSL.

I don’t see any way to check the hash OOB

Also this same thing came up a few years ago

https://www.linuxquestions.org/questions/linux-newbie-8/reli...

show 1 reply
embedding-shapeyesterday at 3:39 PM

An integrity check where both what you're checking and the hash you're checking against is literally not better than nothing if you're trying to prevent downloading compromised software. It'd flag corrupted downloads at least, so that's cool, but for security purposes the hash for a artifact has to be served OOB.

show 1 reply
maccardyesterday at 4:07 PM

It’s not better than nothing - it’s arguably worse.