Resource icon

Checksum versus digital signature: two different file checks

A checksum or cryptographic hash is a fingerprint calculated from a file. If the file changes, its hash usually changes. A digital signature uses cryptography to associate a file with a signer and detect later modification. Neither check, alone, proves that the program is safe to run.

A useful example​

A developer publishes a SHA-256 value on its official site. You calculate the downloaded file's SHA-256 value and compare them exactly. A match supports that you obtained the same bytes the developer described, provided the site itself is authentic. Separately, Windows may show a valid signature from the expected publisher. A scam site can publish its own matching hash, and malicious software can have a valid signature.

Use both in context​

Start with the real download source. Then compare any official hash and inspect the signer when provided. Microsoft's Get-FileHash documentation explains local hash calculation. If either check fails, stop and obtain the file afresh; do not bypass a warning because the filename looks right.

Practical distinction​

A matching hash from an untrusted mirror says only that the mirror and file agree. Obtain the expected value independently from the developer's verified channel.
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack