<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Take advantage of md5 checksums for download validity</title> <atom:link href="http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sun, 12 Feb 2012 04:50:20 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: Generate MD5 Checksums on Windows &#124; Whatsup</title><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/comment-page-1/#comment-994993</link> <dc:creator>Generate MD5 Checksums on Windows &#124; Whatsup</dc:creator> <pubDate>Mon, 08 Mar 2010 07:35:11 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=18689#comment-994993</guid> <description>[...] internet) standard has, for years, been checking the md5 hash. Now, there&#8217;s plenty of info on the web about creating or checking MD5 or SHA-1 checksums for UNIX or Linux users, but not very much about doing the same on [...]</description> <content:encoded><![CDATA[<p>[...] internet) standard has, for years, been checking the md5 hash. Now, there&#8217;s plenty of info on the web about creating or checking MD5 or SHA-1 checksums for UNIX or Linux users, but not very much about doing the same on [...]</p> ]]></content:encoded> </item> <item><title>By: Kirill</title><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/comment-page-1/#comment-920941</link> <dc:creator>Kirill</dc:creator> <pubDate>Sat, 21 Nov 2009 22:58:33 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=18689#comment-920941</guid> <description>@martin english: File Checksum Integrity Verifier is very good. Thank you. But  when I create an exceptions list and try to use it with -exc parameter it is not working. What can you advise?</description> <content:encoded><![CDATA[<p>@martin english: File Checksum Integrity Verifier is very good. Thank you. But  when I create an exceptions list and try to use it with -exc parameter it is not working. What can you advise?</p> ]]></content:encoded> </item> <item><title>By: Rico</title><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/comment-page-1/#comment-920598</link> <dc:creator>Rico</dc:creator> <pubDate>Sat, 21 Nov 2009 07:47:52 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=18689#comment-920598</guid> <description>Honestly, the reason i use checksums  these days are to verify that large files have been downloaded completely. i&#039;ve had the occasional Linux ISO that seemed to download correctly but after some troubleshooting, i&#039;d find that the checksum didn&#039;t match the one posted. It&#039;s not a concern with torrents, but torrents can be slower than a superfast web server.
There is the issue of malicious code, but honestly i trust my [open] sources and while it&#039;s possible malicious code could be slipped in, it&#039;s such a rare occurrence that i&#039;m really not concerned. Not the most secure security model, i know, but i&#039;ve yet to have it fail me in the fifteen or so years i&#039;ve been downloading from remotes sources.</description> <content:encoded><![CDATA[<p>Honestly, the reason i use checksums  these days are to verify that large files have been downloaded completely. i&#8217;ve had the occasional Linux ISO that seemed to download correctly but after some troubleshooting, i&#8217;d find that the checksum didn&#8217;t match the one posted. It&#8217;s not a concern with torrents, but torrents can be slower than a superfast web server.</p><p>There is the issue of malicious code, but honestly i trust my [open] sources and while it&#8217;s possible malicious code could be slipped in, it&#8217;s such a rare occurrence that i&#8217;m really not concerned. Not the most secure security model, i know, but i&#8217;ve yet to have it fail me in the fifteen or so years i&#8217;ve been downloading from remotes sources.</p> ]]></content:encoded> </item> <item><title>By: martin english</title><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/comment-page-1/#comment-920517</link> <dc:creator>martin english</dc:creator> <pubDate>Sat, 21 Nov 2009 05:18:42 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=18689#comment-920517</guid> <description>Windows users wanting to create or verify MD5 or SHA-1checksums need to look at http://support.microsoft.com/kb/841290</description> <content:encoded><![CDATA[<p>Windows users wanting to create or verify MD5 or SHA-1checksums need to look at http://support.microsoft.com/kb/841290</p> ]]></content:encoded> </item> <item><title>By: Captain Canuck</title><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/comment-page-1/#comment-920295</link> <dc:creator>Captain Canuck</dc:creator> <pubDate>Fri, 20 Nov 2009 21:03:20 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=18689#comment-920295</guid> <description>Is it common for people to digitally sign their md5checksum?</description> <content:encoded><![CDATA[<p>Is it common for people to digitally sign their md5checksum?</p> ]]></content:encoded> </item> <item><title>By: Jack Wallen</title><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/comment-page-1/#comment-920016</link> <dc:creator>Jack Wallen</dc:creator> <pubDate>Fri, 20 Nov 2009 12:23:44 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=18689#comment-920016</guid> <description>@Captain Canuck: That is true. You could, however, create your MD5 hash and then digitally sign it.</description> <content:encoded><![CDATA[<p>@Captain Canuck: That is true. You could, however, create your MD5 hash and then digitally sign it.</p> ]]></content:encoded> </item> <item><title>By: Captain Canuck</title><link>http://www.ghacks.net/2009/11/20/take-advantage-of-md5-cecksums-for-download-validity/comment-page-1/#comment-919750</link> <dc:creator>Captain Canuck</dc:creator> <pubDate>Thu, 19 Nov 2009 23:17:14 +0000</pubDate> <guid
isPermaLink="false">http://www.ghacks.net/?p=18689#comment-919750</guid> <description>&quot;What if someone hacked into the server and replaced the file with a bogus file that contained malicious code?&quot;
Wouldn&#039;t that someone also upload another md5 hash matching the malicious replacement?
usually the md5hash file is in the same directory as the download.</description> <content:encoded><![CDATA[<p>&#8220;What if someone hacked into the server and replaced the file with a bogus file that contained malicious code?&#8221;</p><p>Wouldn&#8217;t that someone also upload another md5 hash matching the malicious replacement?<br
/> usually the md5hash file is in the same directory as the download.</p> ]]></content:encoded> </item> </channel> </rss>
