4 ms·
For those who like me are wary of running unverified binaries: - checksums: https://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/latest-mozilla-aurora/firef
by bigbango 12y ago
For those who like me are wary of running unverified binaries:
- checksums: https://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/latest-mozilla-aurora/firefox-35.0a2.en-US.linux-x86_64.checksums https://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/late...
- signatures: https://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/latest-mozilla-aurora/firefox-35.0a2.en-US.linux-x86_64.checksums.asc https://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/late...
- signing key: https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/latest/KEY https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/lat...
edit: reformatting
2nd edit: added https
- skrebbel 12y agoYou're wary of running unverified binaries but you're OK when they're verified by a checksum downloaded over unencrypted HTTP?
- bigbango 12y agoThanks, I was so focused on finding the files that I forgot.
- MichaelGG 12y agoThe criticism is the same: You're worried about running binaries from a particular source, but will accept the signatures from the same source?
- bigbango 12y agoYes, when I don't have any out of band method for obtaining the key. Also, the sources aren't the same, the binary is downloaded from a mirror / CDN while the links I posted are from the main FTP server. edit: grammar corrections