• pinknoise
    link
    fedilink
    arrow-up
    2
    ·
    3 years ago

    So better show the checksum after downloading

    If you got the checksum via a different channel or if it’s signed with a key you’ve got from elsewhere. (ideally, or just TOFU) Otherwise you’re still “only” trusting the https connection.