|
|
|
|
|
by kylebenzle
955 days ago
|
|
I don't agree, it's dead simple: For your example, 1. Download the software form the official website. 2. Verify the signature. 3. Done. If you are very concerned, you can double check the signature from a previous version from the Way back Machine. What are the chances the official site AND the archive were both compromised? |
|
Look at your list of CAs sometime. There's multiple national organizations there. Controlled by a government.
And any of those will be deemed as valid, so if you go to https://www.torproject.org/download/ and it's signed by a Chinese CA for some reason, to your browser that's perfectly fine.
> What are the chances the official site AND the archive were both compromised?
You're talking about a piece of software that's designed to hide stuff from state level actors. If you're in actual need of such a thing, that threat is pretty damn serious.