04.10.2014, 06:09, "Karol Babioch" <[email protected]>:

> Use GPG to verify the integrity of the download and calculate the
> checksum locally for yourself. Users of your package have to trust you
> anyway, as you can basically do anything to your package, anyway.
>
> Best regards,
> Karol Babioch

OK, you have a point, understood.
Tx. 

@ Charles Bos: ^^^ the logic I was missing. Tx. 

Reply via email to