[pca] MD5 value for pca download only in "hover window"

Laurent Blume laurent at elanor.org
Tue Aug 9 14:48:28 CEST 2011


On 08/09/11 10:41, Martin Paul wrote:
> Still, IMHO, listing checksums on the same webpage as the downloadable
> file doesn't make much sense, security-wise. If an attacker can modify
> the script, he most probably can change the checksum on the webpage as
> well. That's why I include the checksum in the postings to the pca-news
> mailing list, to have a second independent channel.
>
> You can also get PCA via HTTPS, BTW:

What about using a PGP signature like many others do? More secure to the 
end user than SSL (which has had a lot of issues), and the public key 
can be published and copied around easily.

Laurent



More information about the pca mailing list