Comment 10 for bug 1883272

Revision history for this message
Steve Langasek (vorlon) wrote :

Verifying SHA256SUMS without verifying gpg signatures is only useful for detecting corruption, not a malicious attack, with or without https.