• pinknoise
      link
      fedilink
      arrow-up
      2
      ·
      3 years ago

      So better show the checksum after downloading

      If you got the checksum via a different channel or if it’s signed with a key you’ve got from elsewhere. (ideally, or just TOFU) Otherwise you’re still “only” trusting the https connection.