• 0 Posts
  • 10 Comments
Joined 2Y ago
cake
Cake day: Jun 04, 2023

help-circle
rss

There’s an Expedition going on for the next 6 weeks in NMS. It’s like a self-contained mega-questline. Start a new single player game and choose “Expedition”. They give you lots of upgrades along the way and you’ll see bases and messages from other players along the same path.


There will be metal parts on the microwave somewhere, and they will be properly grounded into the power socket. Maybe the back panel.



Well, time to go watch Black Mirror again. You know, the one with the robot dog that hunts you, or the one with the quadcopters that kamikaze tap you on the head with explosives?





In other words, if the sha matches, then it wasn’t corrupted during downloading. If the signature matches, then it wasn’t tampered with before you downloaded it.

There’s also a third check. Even if the certificate signature is valid, you have to have confidence that the certificate is authentic and trusted to be from the original author. This is usually done by having a trusted third party sign the certificate with another, more trusted, certificate.


If you get the sha256 from the same place you got the main file, then anyone tampering with the main file could also recalculate the sha256 to match the tampered file. A signature signed with a certificate uses complex math (public-key asymmetric cryptography) to give some certainty that the signed content (the sha256) is the same sha256 that the original file author created. It’s not mathematically feasible to recalculate the certificate signature. Why don’t we just sign the whole original file with the public-key crypto and skip the sha256? Because asymmetric crypto is much, much slower than plain symmetric crypto or hash functions. It’s faster and easier to generate the valid hash or key, then sign or encrypt just the smaller key.