Hacker News new | ask | show | jobs
by gavinuhma 1322 days ago
Agree. Although checksums are smaller and easier to copy/paste. Same with a url.

I download the script from A, and the checksum from B. And then I verify them locally. So A and B both need to be compromised. It all assumes the script was safe to begin with, and this just verifies that nothing has changed