Verifying a download with a checksum
Use sha256sum, shasum and Get-FileHash to check a file matches the publisher's checksum.
Publishers often list a checksum next to a download, usually a SHA-256 hash. If your file hashes to the same value, it arrived intact.
Compute the hash
sha256sum ubuntu.isoshasum -a 256 ubuntu.isoGet-FileHash .\ubuntu.iso -Algorithm SHA256Compare with the published value
Compare the two strings carefully. Any difference means the file is corrupted or altered. Many sites publish a file called SHA256SUMS, and on Linux you can check all entries in one go:
sha256sum -c SHA256SUMSIt prints OK for each file that matches and FAILED for any that does not.
The limit of checksums
CarefulIf an attacker can replace both the file and the checksum on the same website, the check proves nothing. Get the checksum from a different trusted channel, or better, verify a digital signature (for example with GPG) when the project provides one.
Checksums protect against corruption and mistakes. Signatures protect against tampering.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.