3 ms·
> This doesn't solve the problem you have in mind - verifying the file is genuine; it solves the problem of verifying that what you got is what you expected Ex
by moremetadata 4y ago
> This doesn't solve the problem you have in mind - verifying the file is genuine; it solves the problem of verifying that what you got is what you expected
Exactly.
> Secondarily, because the files usually sit on a different server than the site itself, the hash lets you detect some cases of your download being tampered with in-flight, or the file itself altered on the server.
That assumes the download file is on a different webserver, but if they can gain access to one server, its not beyond the realms of possibility they can alter the hash values on another webserver.
I just find all this crypto stuff to be misleading whilst it overstates its effectiveness.
- throwawaylinux 4y agoThose cryptographic hashes that sit on the same sever or are under control of the same group that publish the file itself really came about so you could verify untrusted copies like mirrors and CDs, not data integrity or hacks on the trusted source or a connection to the trusted source.
- Joel_Mckay 4y agoActually, the signed hashes tend to only provide a out-of-band chain of accountability. The old Microsoft signed drivers and Application publishers certs were not perfect. This was because the chain of trust eventually breaks down in time (insufficient strength, leaked signing key re-pack, and most people didn't check installer signatures). FOSS projects can also suffer integrity rot on rare occasion, but it tends to be individuals feigning ignorance as their BS is reverted. Archive.org allows one to often search for the CD hash and files of interest in the Wayback Machines snapshot copy of the publishers website. This method does still require the publishers cert or known hash to verify contents are valid. =)