3 ms·
In this case a distribution site which hosts both the hash and the file was hacked. This test is only good for "is the integrity of the download good" not for "
by ultramancool 10y ago
In this case a distribution site which hosts both the hash and the file was hacked. This test is only good for "is the integrity of the download good" not for "is this created by the original developer". An authenticode or PGP signature is much better.
- ambrop7 10y agoIt is good if the compromise is not large-scale or is recent (e.g. only one of the mirrors was compromised, or the compromise is recent enough that search engines and such don't know much about the hacked version).