This just shifts the trust to the checksum. How do you know you downloaded the right checksum? Checksum the checksum?
Whatever you are doing to protect sending the checksum can also be used for protecting the script itself.
Whatever you are doing to protect sending the checksum can also be used for protecting the script itself.
I download the script from A, and the checksum from B. And then I verify them locally. So A and B both need to be compromised. It all assumes the script was safe to begin with, and this just verifies that nothing has changed
Checksum.sh could keep track of checksums. Then an attacker has to alter the original script and checksum.sh.