Do you think showing an md5 hash would help, or is it just Dropbox itself?
Would (for example) dl.huck.sh be better? (I own huck.sh (and huckridge.com and several others) and have a site there, but don't have anything at dl.huck.sh.)
I actually kind of thought that Dropbox would be better than my own webserver, on the assumption that people would trust them more than me. I dunno.
A too-slick website here on HN is a strong deterrent for me.
So would a tarball on Github put you off, do you think? Would you prefer a raw directory listing from Apache at dl.huck.sh (et al)?
Googling "security audit my code" finds several companies that offer such a service. My concern would be (aside from the admittedly non-trivial benefit of just having better code), would it make a difference to anybody that was on the fence about it? I suspect that the matrix of "potential customers" vs "what auditing service they'd trust" is large.
Thank you for the comment.