Re: Should not .torrent files be listed in SHA512SUMS et.al. ?

On Tue, Feb 13, 2018 at 03:41:14PM +0100, Thomas Schmitt wrote:
>after having looked at
>  https://cdimage.debian.org/debian-cd/current/amd64/bt-dvd/
>i wonder whether the .torrent files are sufficently signed on their own.
>At least they are not listed in the *SUMS files.
>Is this a similar security problem as with the .jigdo files ?
>(I have no clue of BitTorrent. So a simple "Don't worry" would be enough.)

As I understand it, BitTorrent works differently so it's not an
issue. People don't grab the .torrent files directly from our http(s)
sites, but instead using the torrent tracker itself.

That's why I've never added the checksums for them.

Steve McIntyre, Cambridge, UK.
"Further comment on how I feel about IBM will appear once I've worked out
 whether they're being malicious or incompetent. Capital letters are forecast."
 Matthew Garrett, http://www.livejournal.com/users/mjg59/30675.html

