Verify Any Download in Under a Minute
The checksum you keep skipping
Every serious download page publishes a hash. SHA-256, most often. It is a one-line string that changes if even a single byte of the file changes. Compare yours against it and you know the file on your disk is the file they shipped.
Most of us skip this. I did for years. Then a corrupted ISO cost me an afternoon of debugging that had nothing to do with my actual problem, and I stopped skipping it.
How to do it on each OS
macOS and Linux ship everything you need:
shasum -a 256 ubuntu.iso
Windows has it in PowerShell:
Get-FileHash file.zip -Algorithm SHA256
Paste the result next to the published hash. Matching strings, byte for byte, mean the file is intact. Any difference at all means the file is not what it claims to be. Download again. There is no "close enough" with hashes; they are all-or-nothing by design.
Where a hash generator fits in
Sometimes you need the reverse. You built the file and need to publish its hash, or you want to compare two strings without opening a terminal. The hash generator computes MD5, SHA-1, SHA-256 and the other common variants in the browser, and the file never leaves your machine.
Two related habits worth stealing
- Generated credentials should come from a password generator, not from your head. Same principle as the checksum: unpredictability is something you compute, not something you improvise.
- Database seeds and test fixtures need unique identifiers. A UUID generator beats counting up from 1 and colliding with real data on the first shared environment.
When this check matters most
Install media, binaries from smaller vendors, anything that traveled through a flaky connection or a shared drive. The check costs under a minute. The debugging session it prevents can cost half a day.
It also covers you against silent truncation. Files that pass through upload limits, email attachments, or old FTP servers in ASCII mode get mangled in ways that survive double-clicking but break on use. The hash sees all of it, because every altered byte changes the output.
And if a vendor publishes no hash at all, that is worth noticing. It says something about how much they think about their supply chain. Not always something damning, but something worth factoring in. The vendors who sign releases and publish sums tend to be the same ones who ship patches on schedule.