Alas Poor Erinaceus@lemmy.ml to Privacy@lemmy.mlEnglish · 1 day agoHow important is it to verify a signature (of say Mullvad Browser)?message-squaremessage-square13fedilinkarrow-up114arrow-down11file-text
arrow-up113arrow-down1message-squareHow important is it to verify a signature (of say Mullvad Browser)?Alas Poor Erinaceus@lemmy.ml to Privacy@lemmy.mlEnglish · 1 day agomessage-square13fedilinkfile-text
minus-squarecatloaf@lemm.eelinkfedilinkEnglisharrow-up4·1 day agoRight. The risk is low, but nonzero. You’ll want to make sure that the key you’re validating is provided through another trusted channel, so that an attacker can’t provide a bad download and have you check it against their bad key too.
Right. The risk is low, but nonzero.
You’ll want to make sure that the key you’re validating is provided through another trusted channel, so that an attacker can’t provide a bad download and have you check it against their bad key too.