Hacker News new | ask | show | jobs
by btrask 3764 days ago
Debian is already outstanding in this regard (and others)!

One minor suggestion would be to provide ISO hashes over HTTPS. It's just as secure as using GPG with fingerprints sent over HTTPS, and it's a lot easier.

The fingerprints (https://www.debian.org/CD/verify) could also be made more prominent (perhaps put on the main download page).

Thanks again!