Because it’s kind of hard! Even if I follow their instructions. Maybe I’m just dumb . . . 🙁

  • catloaf@lemm.ee
    link
    fedilink
    English
    arrow-up
    3
    ·
    14 hours ago

    Right. The risk is low, but nonzero.

    You’ll want to make sure that the key you’re validating is provided through another trusted channel, so that an attacker can’t provide a bad download and have you check it against their bad key too.