Hacker News new | ask | show | jobs
by witty_username 3664 days ago
How would that checksum or digital signature be distributed?

HTTPS checks for authenticity of source (it uses digital signatures). Now, I guess there could be a rogue CA which creates another certificate for 21.co, but excluding that it's fine.