> so in short, checksums only verify that a download was received in tact 
> without
> error, while a GPG signature verifyies the authenticity of the person who
> published it - the level of confidence that i suspect this thread was asking 
> for
> can only be provided by a signature - checksums are far less significant and
> indeed optional when a signature is provuded; as the signature verifies the
> file's integrity also

I would like to add here that is quite common to sign the *checksum* of
a file, instead of the file itself. Since creating the signature is
computationally more expensive than (most) checksum algorithms, this
reduces the system load on both sides of the trust chain, while
providing basically the same result.

-A


-- 

------------------------------------------------------------------------------
my GPG Public Key:                 https://files.grapentin.org/.gpg/public.key
------------------------------------------------------------------------------

Attachment: signature.asc
Description: PGP signature

Reply via email to