-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
> Cause not everyone has bzip2 ...
Why not have both, so the user can choose? Many other
things on the net do just that. That way, I can choose
bz2 for a quick download, or use gz if I am using an
inferior OS :)
While we're on the subject, how about digitally signing the
releases as well? An MD5 checksum is fine, but certainly
won't protect against trojans and other maliciousness that
a pgp signature could prevent.
Greg Sabino Mullane
greg@turnstep.com
PGP Key: 0x14964AC8 200111191132
-----BEGIN PGP SIGNATURE-----
Comment: http://www.turnstep.com/pgp.html
iQA/AwUBO/nc+7ybkGcUlkrIEQLBPgCeM6CXgV0W7WjJBwGhiVj6u8hjPJ8An3Os
fP8flAAcciNI6FfOPyXKsD1B
=00M7
-----END PGP SIGNATURE-----