logoalt Hacker News

ozimyesterday at 6:29 PM1 replyview on HN

I use winget or homebrew, those tools do so for me and if something doesn't match they show an error.


Replies

fuzzy2yesterday at 10:27 PM

Neither WinGet nor Homebrew packages/formulae provide authenticity checks. They have integrity checks for file transfer. That’s it. Where did the file come from when it was entered into the respective repository? No statement.

Whether Authenticode provides a sufficient authenticity check is yet another question, of course. Still, file integrity verification is just a side-effect.