Download pages for operating systems, firmware, and developer tools almost always publish a SHA-256 checksum next to the file. Most people ignore it. That's a shame, because verifying a checksum is the simplest way to confirm a download arrived intact — and it's the difference between "probably fine" and "provably identical."
What a checksum proves
A checksum is the output of a hash function run over the file: same bytes in, same digest out, every time. Change a single bit of a multi-gigabyte image and the SHA-256 digest changes completely. So when your computed digest matches the publisher's, you know the file you hold is bit-for-bit what they released.
Related reading: How to Remain Valuable When Intelligence Becomes Cheap — a 224-page practical book on staying valuable as intelligence gets cheap. $3.84. Read it on Gumroad →
Note the boundary of that guarantee: a checksum proves integrity (nothing changed in transit), not authenticity (that the publisher is who you think). If an attacker compromised the download page, they can replace both file and checksum. For authenticity you need signatures — but integrity alone catches corrupted downloads, truncated transfers, and tampered mirrors.
The right way to verify
- Get the expected digest from a trustworthy source — ideally a second channel, like the project's documentation or release notes, not just the same mirror.
- Hash the file locally with SHA-256 (avoid MD5 and SHA-1 for this; both are broken for integrity purposes).
- Compare the full strings, not the first few characters. Copy-paste both into a diff or compare carefully end to end — attackers count on eyeball fatigue.
If you're staring at a digest and wondering what produced it, the Hash Type Identifier recognizes common hash formats by their shape. And for the companion topic — why password storage needs slow hashes instead of fast ones — see hashing, salting, and why you shouldn't roll your own crypto.
Make it a habit
Verification takes under a minute and eliminates an entire class of "weird install failure" debugging — half of which turn out to be corrupted downloads. For anything that runs with privileges — OS images, firmware, installers — checking the digest isn't paranoia. It's the documented step everyone skips.