How does validating the PGP signature of a downloaded executable against the publisher’s public key show that the binary has not been tampered with?
Websites that host downloadable executables often provide measures to confirm the integrity of the data that is available to download. Such measures include:
Hosting the website under HTTPS;
Providing the SHA-256 sum of the downloaded bin… Continue reading How does validating the PGP signature of a downloaded executable against the publisher’s public key show that the binary has not been tampered with?