Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
flurpitude
on Aug 3, 2016
|
parent
|
context
|
favorite
| on:
Classic Shell hacked with compromised update that ...
I don't see much value in published file hashes when they're hosted on the same site that hosts the files. If someone compromises the download link they're probably in a good position to update the hashes too.
0x0539
on Aug 3, 2016
[–]
The purpose of the hashes isn't to prove the file hasn't been tampered with, its confirm that the file wasn't corrupted during download.
bashinator
on Aug 3, 2016
|
parent
[–]
Then just use checksum instead of an obsolete cryptographic hash.
Join us for
AI Startup School
this June 16-17 in San Francisco!
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: