3 ms·
"2. The trusted sources should provide checksums so you can verify the package before installing it." If the checksum is published to another trusted location,
by donutz 13y ago
"2. The trusted sources should provide checksums so you can verify the package before installing it."
If the checksum is published to another trusted location, in addition to where you download the files, that would help in the case that an attacker compromises both the checksum and the package on the download site.
The developer could post the checksum to Twitter at the same time as making the package available for download. An attacker would need to compromise both Twitter and the download site.