35 ms·
CNET and download used to be, sure. Maybe not so much anymore. I'm just saying official or not, if the checksum matches - it's not malicious. End of story. You
by seangrant 11y ago
CNET and download used to be, sure. Maybe not so much anymore. I'm just saying official or not, if the checksum matches - it's not malicious. End of story.
You're correct though in that just randomly picking mirrors is a bad idea. I seriously doubt your average person is utilizing checksums.
- TeMPOraL 11y ago> I seriously doubt your average person is utilizing checksums. Sure, if you're utilizing checksums the way they should be then go ahead. But honestly, even I don't care that much - my ad-heuristic was sufficient so far :). I should probably start using them. I guess it's like with all things crypto - the UX sucks so bad that most people don't bother.
- discreditable 11y agoChecksums are particularly handy when the original source is inaccessible. In that sort of situation I can google the file name and verify authenticity easily.
- Nadya 11y ago>I'm just saying official or not, if the checksum matches - it's not malicious. End of story. Well...it would take a particularly craft individual and far too much time, but spoofing a malicious MD5 checksum should be considered plausible. The chances of it being malicious, however, are drastically reduced to such a large degree as that it is safe to consider it negligible. (Note: I only make this claim about MD5 checksums, not SHA-1 or SHA-2. I do not consider MD5 secure in any manner and my trust of SHA-1/SHA-2 isn't exactly high either.) I provide SHA-1 and MD5 checksums of any software I distribute - if only because I think it is the proper thing to do. Even if most people don't bother checking them (let alone know how to check them)
- Nadya 11y agoReally? Downvotes for saying MD5 can't be trusted?Here is an article explaining why. http://www.codeproject.com/Articles/11643/Exploiting-MD5-collisions-in-C http://www.codeproject.com/Articles/11643/Exploiting-MD5-col...