An md5 can be created for the trojaned binary and be posted along with it.
Not to mention that the md5 checksum is a very poor choice for this purpose because of the ease of creating md5 collisions.
Not to mention that the md5 checksum is a very poor choice for this purpose because of the ease of creating md5 collisions.
That's the whole point of using a cryptographic signature backed by a web of trust instead of a mere hash.