4 ms·
" Download Audacity Windows Installer - 19.34 MB | version: 2.2.0 | SHA256 signature Download Audacity Windows Zip - 11.31 MB | version: 2.2.0 | SHA256 signat
by hellbanner 9y ago
"
Download Audacity Windows Installer - 19.34 MB | version: 2.2.0 | SHA256 signature
Download Audacity Windows Zip - 11.31 MB | version: 2.2.0 | SHA256 signature
Download Audacity macOs DMG - 28.14 MB | version: 2.2.0 | SHA256 signature
Download Audacity Linux source - 9.72 MB | version: 2.2.0 | SHA256 signature
Download Audacity LADSPA plugins for Mac - zip - 2.74 MB | version: 0.4.15 | SHA256 signature
Download Audacity LADSPA plugins for Windows - installer - 1.44 MB | version: 0.4.15 | SHA256 signature
Download Audacity Mac OS X 2.1.1 - DMG (screen reader accessible) - 38.61 MB | version: 2.1.1 | SHA256 signature
Download Audacity Mac OS X 2.1.1 - ZIP (screen reader accessible) - 16.50 MB | version: 2.1.1 | SHA256 signature
"
How can I trust the website to tell me the correct SHA256 signature?
Shouldn't this be linked to a repository, or ideally something my client can verify the commits are correct?
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- TheAceOfHearts 9y agoWell, for starters, the SHA256 signatures are on both the Audacity website and its FossHub page. You can check if both places match, which makes it less likely to be from an untrusted source. They even have a page explaining how to check the signature. If you're on macOS, before mounting a disk image the system will verify its checksum. Additionally, the default security settings only allows applications from the app store and identified developers. You can use the codesign tool (codesign -dv --verbose /Applications/Audacity.app) to verify the code signature as well as display the signing identity. In this case, it's signed by Paul Licameli, which is the author of this blog post. With that said, it's not foolproof, as the TeamIdentifier is not publicly posted anywhere, someone could possibly create a Developer ID with his name.