Hacker News new | past | comments | ask | show | jobs | submit login

It doesn't have to be a simple hash either. You could have the author/release engineer sign it and then use the signature instead. This somewhat mitigates simple hash collisions



Don't most systems for signing files just sign the hash of the file anyway?


That's an even better idea, I like it!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: