Hacker News new | ask | show | jobs
by pnutjam 2006 days ago
Mdt hashes and signing could have avoided this. Open source stuff always verifies, vote closed source doesn't have that habit.
1 comments

An article I read said that they did provide hashes but they also provided instructions on how to install it anyway if the hashes didn't match.
How is this possibly acceptable? We've given people verifiable proof that this binary is not the one we created, yet users should crack on and install it anyway?