In most cases I only install software from the Trisquel repo but for instance for Trisquel itself, replicant images etc I download the install files and verify them with shasum and gpg. I thought tha such verification is (or can be) crucial to security - but perhaps it is not as useful as I thought?

Reply via email to