2
I thought the point of distributing md5 checksums was so the end user could verify the integrity of the download.
If a high traffic site points me to a mirror site for download, why would I want to verify my download against a checksum that is provided on the mirror?
If someone were going to tamper with binaries on the mirror site, couldn't they also tamper with the checksums? Shouldn't the authoritative site give me the checksum before I download from a mirror so I can check against the main source?
If I can't find a proper checksum on an official site, I'll ask somebody who already has it to grab the hash for me :P – Phoshi – 2009-09-22T14:47:40.113
1Wait, you have friends that understand what a checksum is? My friends would just look at me funny and then ask if I could make their PC run fast again after having downloaded a World of Warcraft trojan. – Joe Holloway – 2009-09-23T14:15:26.770