An unfortunate combination of being “technologically challenged”, fear, paranoia, and limited knowledge of a long list of “problems” with verification has coalesced into a monster. That “monster” has compelled me to seek help from you, the QUBES COMMUNITY.
My question is simple (I hope): is this the correct SHA3-512 hash for the file Qubes-R4.3.0-x86_64.iso…34a6441169b297e50f65323720301b6b6f1ebacf185a1464f8c965877681125a1c9a25c54c24a281f84aa69627e4d5a7cffb4049b55735695e368d1f84cc7aa4 ? A yes or no will suffice. I will compare the yes votes to the no votes and assume that the combined wisdom of the forum is correct. Thank you for your time and help. And,…on an extremely related issue, if you,(dear reader) are perhaps a “qubes developer”, I humbly suggest a possible solution to the pernicious problem of “verification”; Perhaps something similar to “Mint Verify” could be helpful ? I really wouldn’t know; But, it does seem like some of the legwork has already been done. Perhaps it’s a copy and paste situation ! God bless you all, and don’t give up !
File servers have digests, but the convention at the moment of writing is to verify using detached signature:
It would be easier to compare if you could produce sha2-512 - this is what file servers serve.
Thank you for your reply otter2. It seems that the real problem is that when I “sent” the Qubes 4.3.0 .iso file to an attached usb, the subsequent shasum value changes. The .iso file in the downloads folder has the proper value. Copying the file works fine; But when this file is “sent” to usb it is somehow corrupted.
It must not be, the process of verifying image on drive is different: how to re-verify installation media after writing