Checksums for File Integrity
Discussions focus on the use and limitations of checksums and hashes to verify file integrity during downloads, including concerns about compromised checksums and the need for cryptographic signatures.
Activity Over Time
Top Contributors
Keywords
Sample Comments
If only we had checksums or file hash integrity.
Will they add checksums to verify the checksums?
Surely this isn't a problem with checksums/hashes to verify the integrity of the files?
Doesn't a checksum verify that the file you have is the same one the distributor intends you to have?
They have checksum hashes but not crypto verifiable signatures.
Were the posted checksums also replaced?
Couldnt this be countered by writing your own script checking the hash of the files X times a day?
But they're adding checksums right? Anyone see any holes in that?
If the binary you're downloading might have been modified, how do you know that the hash you're checking against hasn't been as well?
You're right, I confused checksum with hash.