Pergunta

I'm trying to install the Java JDK. The download page does not use HTTPS. I downloaded the .dmg file anyway; when I open it, Finder spends some time verifying it and then I have the option to install it.

How can I know whether it's safe to install?

Foi útil?

Solução

You don't know.

The finder just checks the disk image is a valid disk image.

To check that what you have downloaded matches what is on the server you need to do more checking. A common way is to calculate a hash on the downloaded data and compare with a hash published by the internet site.

Then how do you know that the app you have downloaded won't format your disk? Again you don't You have to use your judgement as to whether the publisher is trustworthy enough.

If you went to Oracle's page directly or via a link from a trustable source then ok but if from a link from a mail from someone who has never sent you a mail before then probably not a good idea.

Licenciado em: CC-BY-SA com atribuição
Não afiliado a apple.stackexchange
scroll top