Delve into the wondrous labyrinth of sparkling images that is the Debian build output.

  • 𝘋𝘪𝘳𝘬@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    1 day ago

    Also: If someone manages to tamper with the downloadable ISO … they likely will be able to tamper with the signature files, too.

    • irotsoma
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      Yeah I think hashes in the same folder are only valuable as a check to make sure you downloaded the file successfully. Which isn’t a big issue for at least the around 80% of internet users who have access to broadband. They are only useful for security if the hash is on the website that you click on and then you download and verify it manually.