Hashing vs. Signing Binaries

后端 未结 4 1819
情深已故
情深已故 2021-02-14 11:00

If you want to ensure that a file is valid (untampered and came from the correct/expected source), there are two things you can do: hashing, and signing

4条回答
  •  无人及你
    2021-02-14 12:02

    Signing verifies two things -- that the file has not been tampered with, and the identity of the signer. If you can be sure that entity giving you the hash is absolutely the entity that is supposed to be giving you the file, then the two are equivalent. Signing and certificate authorities are a way of ensuring that trust relationship.

提交回复
热议问题