<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Official checksums for current sav-linux-free-9.tgz</title><link>https://community.sophos.com/on-premise-endpoint/f/sophos-anti-virus-for-linux-basic/93722/official-checksums-for-current-sav-linux-free-9-tgz</link><description>Dear Sophos Team, 
 Could you please post the checksums for the current Sophos Antivirus for Linux installation file? According to your download website 
 https://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-linux.aspx 
 it is version</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Official checksums for current sav-linux-free-9.tgz</title><link>https://community.sophos.com/thread/364160?ContentTypeID=1</link><pubDate>Wed, 07 Feb 2018 11:11:35 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:388b1aa0-434c-4361-821e-a03680c6f339</guid><dc:creator>DMatthew</dc:creator><description>&lt;p&gt;Kai, I fully agree and share your concerns and frustrations.&amp;nbsp; Checksums are common place and have stood the test of time. I am certainly baffled that Sophos does not provide this to help ensure their installers have not been tampered with by a 3rd party (not a new concept).&amp;nbsp; I would add though that the installer and checksum info should come from two different server sites&amp;nbsp; (and keeping the downloader and checksum in sync really should not be that difficult, either).&lt;/p&gt;
&lt;p&gt;The last time I wanted to install Sophos I saw this same old thread that has essentially been ignored. I ended up just turning away and giving up on it.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Official checksums for current sav-linux-free-9.tgz</title><link>https://community.sophos.com/thread/339500?ContentTypeID=1</link><pubDate>Fri, 07 Jul 2017 07:37:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:370a5ffd-cd00-4197-9094-8d666e283cf5</guid><dc:creator>QC</dc:creator><description>&lt;p&gt;Hello Kai,&lt;/p&gt;
&lt;p&gt;&lt;span id="fragment-404728274_QuoteText" class="field-item-description user-defined-markup"&gt;&lt;span style="color:#008000;"&gt;&lt;em&gt;security [...] basic means of file checking&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;it gives IMO a false sense of security as it is too often applied in the opposite direction - if the checksum matches then the file is ok. The case of accidental corruption of the download aside (protocols and applications should ensure integrity in most cases, internal structures and dependencies make many of the remaining errors obvious, the chance that a flipped bit goes unnoticed and has harmful consequences is ...?) &lt;br /&gt;Keep in mind you just transfer the trust from the download to the checksum. You think the download might be compromised - how can you tell the checksum is genuine? Are community.sophos.com and downloads.sophos.com (or whatever) indeed independent sources? Wouldn&amp;#39;t someone who is able to compromise the download also be able to compromise the checksum?&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve never heard an official statement in this direction though (I just conjecture what could be the reason for not publishing checksums)&lt;/p&gt;
&lt;p&gt;Christian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Official checksums for current sav-linux-free-9.tgz</title><link>https://community.sophos.com/thread/339481?ContentTypeID=1</link><pubDate>Fri, 07 Jul 2017 05:30:27 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fb4483a1-5b5c-4490-9904-d295d7551dbe</guid><dc:creator>Kai S</dc:creator><description>&lt;p&gt;Hi Christian,&lt;/p&gt;
&lt;p&gt;Many thanks for the quick response.&lt;/p&gt;
&lt;p&gt;Yes, exactly the purpose you described: Making sure that the file is ok, having something like a secure chain from the download website and its SSL certificate to a checksum of the file I want to download.&lt;/p&gt;
&lt;p&gt;I find it difficult to understand why&amp;nbsp;a security company would not offer these basic means of file checking, and how they would want somebody&amp;nbsp;to trust their products, be they free or paid for.&lt;/p&gt;
&lt;p&gt;From a practical side of things, they could just post the checksums of new versions on this very forum, making it easy for everybody interested to find it and verify. If there are different versions around and they cannot get them in sync they could just post a new checksum whenever a new version becomes available and the public would be able to find the correct checksum for the file they downloaded, for example in a sticky post.&lt;/p&gt;
&lt;p&gt;Hopefully, somebody from Sophos will read this, but the last time they responded to a checksum for Linux Sophos question seems to have been 20 months ago.&lt;/p&gt;
&lt;p&gt;Thanks again!&lt;/p&gt;
&lt;p&gt;Kai&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Official checksums for current sav-linux-free-9.tgz</title><link>https://community.sophos.com/thread/339317?ContentTypeID=1</link><pubDate>Thu, 06 Jul 2017 07:01:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:49e226e3-11f0-48cb-95f0-9a4f07fdeaf5</guid><dc:creator>QC</dc:creator><description>&lt;p&gt;Hello Kai,&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:75%;"&gt;[I&amp;#39;m not Sophos]&lt;/span&gt;&lt;br /&gt;I know that checksums are popular but, frankly, what&amp;#39;s the real benefit here? To check whether the download is incomplete or corrupted? Or that the download is genuine?&lt;/p&gt;
&lt;p&gt;Seems that Sophos doesn&amp;#39;t really believe in publishing checksums for these downloads. They did so some time ago for certain products, unfortunately download and published checksum weren&amp;#39;t always synchronized (presumably causing even more questions than the mere absence of the latter).&lt;/p&gt;
&lt;p&gt;Christian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>