[A HREF="http://example.com/SomeProgram.exe" ExpectedSha256="..."]Download[/A]
If clicked, the download is checked and is quietly discarded if the hash is wrong.
[A HREF="http://example.com/SomeProgram.exe" ExpectedSha256="..."]Download[/A]
If clicked, the download is checked and is quietly discarded if the hash is wrong.
Edit: To clarify, I mean it could show the warning before the browser does the rename of the file from the temporary download file to the final filename.
If I could prove that the first 5% of a file is intact given the final hash, and repeat that proof continuously as the download proceeds, then it wouldn’t be wasteful.
IANAC
100% hash: 12344567
10% hash: 7251abed
That the 10% hash is a valid candidate for eventually becoming 12344567, assuming the other 90% checks out?
Courtesy of Wikipedia on the matter, at the MD5 page:
MD5("The quick brown fox jumps over the lazy dog") =
9e107d9d372bb6826bd81d3542a419d6
MD5("The quick brown fox jumps over the lazy dog.") =
e4d909c290d0fb1ca068ffaddf22cbd0
The addition of the . at the end has indeterminable effects on the resulting hash. Unless the protocol is defined such that the blob is hashed in blocks of known size and that's what's being checked against (as opposed to the full-blob hash), I don't think it's solvable.Someone with more street cred on this matter, please correct me if I'm wrong!
EDIT: What about a "Hey, server! I'm 2MBs in, and I got hash blahblohblablablaaah; am I doing fine?" protocol? #terribleideas
However, a second hash of 10% of the file would work fine. You can even truncate it if saving a few bytes is that important (since you will check the full file hash later), although I suspect even a page with a bunch of downloads would be fine with a couple of extra hashes per file. While most APIs don't expose this possibility, most hash algorithms can spit out the full hash of the file up to any intermediary points with very little additional work. Or there could be seperate hashes for different blocks of data like P2P protocols do and store them all in a separate file on the https site.
However, the main issue is that these days it is very easy to just use https, most likely easier than any other solution. Browsers encouraging people to care by showing warnings should be very helpful in increasing the number of sites using https.
/s