3 ms·
Wouldn't the decompression fail in that case?
by OrgNet 7y ago
Wouldn't the decompression fail in that case?
- roelvandijk 7y agoThe idea is to publish the checksum of the archive separately. After downloading the archive you can calculate its checksum and compare with the published checksum. If they differ you known something is up (possibly bad). When a browser helpfully decompresses the archive you can no longer perform this check.
- OrgNet 7y agoIf it fails to decompress because the file is corrupt, the browser would more then likely keep the archive? But if someone replaces the archive with a malicious file that decompress normally, he will also probably change the listed checksum on the download page....
- k1t 7y agoThe actual download might be hosted by 3rd party mirrors. You can compare the checksum to the one on the author's site to ensure the mirror provider didn't alter the file.
- kadoban 7y agoThere are signature schemes that can fix that issue, and cases where it's useful anyway, like: Many linux distro isos are available from several different mirrors. Having a secure hash on the original site with the links to mirrors means I don't have to trust the mirror(s). Another case where the archive hash is useful is when there's some public key crypto involved. I can have a public key from a publisher (gotten either out-of-band or in the past) and the hash can be signed so I can verify it. These schemes would mean that an attacker would at the least need to have compromised a site for an extended period of time (if I have history with the site, the first visit it doesn't do anything extra), or in the case of out-of-band key sharing, multiple communication methods might need to be compromised for an attack to succeed. But yes, in the common case a hash next to a file link hosted on the same domain really doesn't do anything.
- deleted 7y ago[deleted]