Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can usually get PGP signed hashes for tarballs distributed by serious entities. If someone is distributing software and provides no way to check that it is genuine, you shouldn't run it...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: