Hacker News new | ask | show | jobs
by xtagon 976 days ago
See: https://keepass.info/integrity.html (you may want to manually type it into the address bar...) and download their PGP keys. That way you can verify KeePass downloads using their signatures, which you can save and sign with your own key to really verify the paranoid way. If you ever land on a bad download site, you'll know something's up after you verify and it doesn't match.
1 comments

Also, on Windows, both the installer and the main executable are digitally signed with a valid code signing cert: 'Open Source Developer, Dominik Reichl'