logoalt Hacker News

nailer • today at 2:41 AM • 1 reply • view on HN

Every download of a piece of software could be unique.


Replies

t-writescode • today at 5:32 AM

Which is why we have sha1, md5 and sha256 hashes on display, so you can validate with a very high level of certainty, especially for sha256 at least for now, that the file is the same one.

We have existing paradigms for this.

Additionally, installers are signed with certificates on Windows.

All of these are strictly more trustworthy than curl | bashing.