Hey,
Is there any possibility of getting detached signature files from Andrew for the downloads?
I don't mean signature files for checksums (though they're useful), but checksums don't detect if files on a server have been tampered with. Since hackers have managed to replace files w/ maliciously altered versions on lots more than one or two major organizations, I'd appreciate detached .asc files, signed with Andrew's public key.
I have an important security concern I'm hoping you can help solve.
Question 1:
How can I be sure the .xml updates are legitimate and from you,
what checks are in place? Is there a method to verify the updates via hash or key or otherwise?
Question 2:
Can I accept 'all' updates at once without having to click OK to each one?