• mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    1 year ago

    “Eh, I’m sure the download was fine, I don’t need to check the SHA256”

    vs

    “PGP key or I’m not even visiting the repo by piggybacking the wifi outside walmart so the feds can’t track me”

    • ReginaPhalange@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      I don’t even get the first one. The download is malicious meaning the hosting site was compromised meaning the hash posted along with the download link is compromised too.