I am new to this so please bear with me. I was downloading a VM image and I was told to check the MD5. Naturally, I did but wondered,
If a hacker would change the file to be downloaded from the site, wouldn't the hacker also be able to change the checksum on the site to make the file look genuine?
If this is the case, wouldn't this defeat the purpose or is the checksum not really meant for hackers but only problematic downloads over a network?