4 Replies - 485 Views - Last Post: 05 September 2017 - 01:28 AM

#1 Alex_C  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 18
  • Joined: 03-September 16

Show SHA256 below the download link

Posted 04 September 2017 - 09:20 AM

Hi, an user asked me if I could add the SHA256 with the installer I provide, for security reasons.

I checked the hash of the file using powershell (followed the procedure here), and I'm thinking about publishing it in the website below the download link.

Is this ok to do?

Seems all fine to me, but I've decided to double-check here anyway :)

Thanks in advance!

This post has been edited by Alex_C: 04 September 2017 - 09:27 AM


Is This A Good Question/Topic? 0
  • +

Replies To: Show SHA256 below the download link

#2 Atli  Icon User is offline

  • Enhance Your Calm
  • member icon

Reputation: 4238
  • View blog
  • Posts: 7,216
  • Joined: 08-June 10

Re: Show SHA256 below the download link

Posted 04 September 2017 - 12:48 PM

Sure, it's fine. It's not like file hashes are sensitive info, it just lets your users double check that the file they got is the same one you are sending.
Was This Post Helpful? 1
  • +
  • -

#3 Alex_C  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 18
  • Joined: 03-September 16

Re: Show SHA256 below the download link

Posted 04 September 2017 - 03:15 PM

View PostAtli, on 04 September 2017 - 12:48 PM, said:

Sure, it's fine. It's not like file hashes are sensitive info, it just lets your users double check that the file they got is the same one you are sending.


Thank you for reassuring me!

Another question:

Is there a canonical way of doing it, or simply publishing the SHA256 (like this, "SHA256: xxxxxxx...") string below the download link is generally considered ok?

Thanks!

This post has been edited by Alex_C: 04 September 2017 - 03:25 PM

Was This Post Helpful? 0
  • +
  • -

#4 Skydiver  Icon User is online

  • Code herder
  • member icon

Reputation: 5889
  • View blog
  • Posts: 20,098
  • Joined: 05-May 12

Re: Show SHA256 below the download link

Posted 04 September 2017 - 05:11 PM

It really depends on the design esthetics of your download page. Some Web UI designers may balk at it because it looks too geeky and clutters the page, but other Web UI designer may say that your target audience is security conscious and geeky enough to accept the hash being shown on the page. You could compromise and have hashes displayed only after a button is clicked or the binary is downloaded.
Was This Post Helpful? 1
  • +
  • -

#5 Alex_C  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 18
  • Joined: 03-September 16

Re: Show SHA256 below the download link

Posted 05 September 2017 - 01:28 AM

@Skydiver

Totally understood. Many thanks!

This post has been edited by Skydiver: 05 September 2017 - 08:59 AM
Reason for edit:: Removed unnecessary quote. No need to quote the post above yours.

Was This Post Helpful? 0
  • +
  • -

Page 1 of 1