Delve into the wondrous labyrinth of sparkling images that is the Debian build output.

  • 𝘋𝘪𝘳𝘬@lemmy.ml
    link
    fedilink
    arrow-up
    9
    ·
    6 个月前

    Also: If someone manages to tamper with the downloadable ISO … they likely will be able to tamper with the signature files, too.

    • irotsoma@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      3
      ·
      6 个月前

      Yeah I think hashes in the same folder are only valuable as a check to make sure you downloaded the file successfully. Which isn’t a big issue for at least the around 80% of internet users who have access to broadband. They are only useful for security if the hash is on the website that you click on and then you download and verify it manually.