Hacker News new | past | comments | ask | show | jobs | submit login

They have been for decades! Most scene releases that are packed will include an SFV file that contains the checksums of each of the package files so that you can check the file integrity.

Obviously those can be repacked and faked so you'd have to check multiple sources to ensure you get a genuine release, but yeah the scene groups are as usual way ahead of everyone else.




I meant signatures, not checksums. A signature chain would avoid the repackaging problem if the signer's public key was distributed out-of-band. Groups and distributors alike could add their own signatures to create multiple possible trust boundaries.

I think the scene groups are a traditional bunch that in some respects are years behind because of it. I remember in maybe 2005 I'd still download releases that were split into floppy sized RAR files. Possibly, this tradition carried on for so long because the scene was so keen to shame groups that didn't package like everyone else. I don't know how it is now but I'm hoping they got over splitting releases.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: