Hacker News new | ask | show | jobs
by rfoo 1236 days ago
> gpg seems to be what all of them use

GPG signs a hash of the message with the private key, and you verify that the signature matches the file hash.

Oh wait, what hash? :clown: