HN user

_mpu

19 karma
Posts0
Comments10
View on HN
No posts found.

In your case, PGP would be the best and not so hard to implement.

If you don't want/know how to use PGP you can also publish the SHA1 sums of the files available on your download page. It's better than nothing.

The second alternative is weaker because an attacker would simply need to change the binary and the sum on the website. In the PGP case, the attacker must get access to your PGP private key, and provided that you use PGP reasonably (no private key on your web server), this is harder.

Are people serious when they say they "love the idea" of copying a binary to their server to run a blog service? It sounds very much like installing a shareware in the 90s.

In the current context (NSA, generalized spying, ...), I hope that everybody realizes it's not an ideal way to distribute software.

Please provide cryptographic signatures or at least sha sums, if you really think this is the best way to distribute software.

I agree. I don't understand why people keep trying to deface C. This "indentation" scheme is by all mean ridiculous and not practical. One thing we learn from this article is that the author actually does not program in C.