Oh, okay, so maybe I misread the sentence. I thought the implication was they used crc32 as opposed to HTTPS. Not sure why you need an additional layer in addition to https- as long as the certificate chain is setup properly. And again, you’re not gaining additional security if you submit the hash (or a gpg key) through the same channel. So if they already use https and just want to check for broken downloads, crc32 is perfectly fine. It’s just security theater at that point.
- 0 Posts
- 3 Comments
Joined 1 year ago
Cake day: April 16th, 2025
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.
- ren@reddthat.comtoTechnology@lemmy.world•AMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flawEnglish1·3 months ago
- ren@reddthat.comtoTechnology@lemmy.world•AMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flawEnglish3·3 months ago
What does it matter if it’s CRC or sha512 if they are using an unsecured connection to transmit them? A stranger who has already acquired capability to modify the payload in transit can also modify the checksum. A better hash will not solve this problem.
I bet you could even get some foaming-at-the-mouth anti-AI activists to endorse Israel’s right to resist if Israel decides to ban all AI. Worth a thought, Bibi.