Because it’s kind of hard! Even if I follow their instructions. Maybe I’m just dumb . . . 🙁

  • Anna@lemmy.ml
    link
    fedilink
    arrow-up
    4
    ·
    3 days ago

    You should always verify signature and hash for any software you are installing but also keep in mind that if someone was really trying to send you a malicious download then there’s good chance that they will also deliver you a malicious signing key and hash. And there is really no good solution. If it is critical you can try to get signings keys from different places and with different IPs and maybe even different devices but pick and choose how long do you want to go down this rabbit hole.