Hacker News new | ask | show | jobs
by _wldu 2141 days ago
They are for integrity checking, not security. PGP signatures are better for the scenario you are describing.
1 comments

Is it a common scenario nowadays to download a file and have it be corrupted? I don't think I've ever had that happen (Though perhaps I wouldn't know, because I don't use these checksums! Though if a package is corrupted and it doesn't noticeably degrade, is it really corrupted? Hm... philosophy of internet downloads)