• gomp@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    2 months ago

    Installing a .deb is what I was thinking about.

    Even a signed tarball is better than curl|sh.

    If you have a pre-shared trusted signature to check against (like with your distro’s repos), yes. But… that’s obviously not the case since we are talking installing software from the developer’s website.

    Whatever cryptografic signature you can get from the same potentially compromised website you get the software from would be worth as much as the usual md5/sha checksums (ie. it would only check against transmission errors).