Why developers put the installer/executable and the file checksum on the same server? [duplicate]

On https://exiftool.org/ , there is a link to https://exiftool.org/exiftool-12.01.zip and https://exiftool.org/checksums.txt .
Both the ZIP archive and the checksum hash are hosted on the same machine. This means that an attacker who has c… Continue reading Why developers put the installer/executable and the file checksum on the same server? [duplicate]