Hacker News new | past | comments | ask | show | jobs | submit login

It definitely does help. We've seen malicious actors introduce "bad things" into legitimate packages [1]. So hashes help identify what you got, but doesn't necessarily prevent you from getting something you didn't intend.

[1] https://www.cisa.gov/uscert/ncas/current-activity/2021/10/22...




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: