Hacker News new | ask | show | jobs
by subway 2613 days ago
Sure, but who tells the client what the correct hash is?
1 comments

If you're the entity who created the image you can retain the original hash and verify it against the downloaded copies. But that kind of defeats the purpose of being able to download docker images across distributed hosts.

They'd really need to be signatures attached to the images, not just hashes.