On 16-09-2011 20:49, ved...@nym.hush.com wrote:

>> Why not also host a copy of the existing binary?
> 
> Because then who is to say that it wasn't tampered with?

OK, then what about a direct link to the version of the installer still
present on ftp.gnupg.org?

> Although, 
> [and am over my head here, so please correct if wrong],
> if there *could* be a way of providing instructions on compiling, 
> so that the resultant compiled file would always have the same 
> hash,

Unlikely, since tyhe Windows executable file format contains a timestamp
within the binary.

-- 
Met vriendelijke groet / With kind regards,
Johan Wevers

PGP/GPG public keys at http://www.xs4all.nl/~johanw/pgpkeys.html


_______________________________________________
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to