HN2new | past | comments | ask | show | jobs | submitlogin

Downloading Tor from an inofficial source sounds like a recipe for trojans though... I don't think most people will have Erinn's signature to verify.


It shouldn't matter where you're downloading the TBB binary, since you're going to verify the signature before trusting it, right? Surely you wouldn't just assume it was legitimate, and then install it.


Business idea: signature database with web interface. So download from anywhere, and look up the signature on the database to verify its authentic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: