appzasGamesToolsDevLearnReferenceNetworkTimeCalculatorsCompareLLM prices

Verifying a download with a checksum

Lesson 4 of 48 minBeginner

Use sha256sum, shasum and Get-FileHash to check a file matches the publisher's checksum.

Publishers often list a checksum next to a download, usually a SHA-256 hash. If your file hashes to the same value, it arrived intact.

Compute the hash

Linux
sha256sum ubuntu.iso
macOS
shasum -a 256 ubuntu.iso
Windows PowerShell
Get-FileHash .\ubuntu.iso -Algorithm SHA256

Compare with the published value

Compare the two strings carefully. Any difference means the file is corrupted or altered. Many sites publish a file called SHA256SUMS, and on Linux you can check all entries in one go:

sha256sum -c SHA256SUMS

It prints OK for each file that matches and FAILED for any that does not.

The limit of checksums

CarefulIf an attacker can replace both the file and the checksum on the same website, the check proves nothing. Get the checksum from a different trusted channel, or better, verify a digital signature (for example with GPG) when the project provides one.

Checksums protect against corruption and mistakes. Signatures protect against tampering.

Test yourself

Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.

HintThe command name contains the algorithm and "sum".
2. Why is a checksum published on the same page as the download only weak protection?
3. Which tool protects against tampering rather than just corruption?

Key terms