How to validate that a client application file is authentic, even if downloaded through an untrusted network.
Hash
functions can be used to create a unique digital signature -- a
hash -- for any file. Lantern captures this hash when
our application is compiled and publishes them on GitHub:
lantern-binaries. Users can run the same hash function
(SHA256) on downloaded copies to assure they are an exact
match, proving the file to be an authentic and unaltered copy of the
original.
Most operating systems have built-in hash functions. Follow the steps below for your operating system to generate the hash for a file.
[!IMPORTANT] Make sure to replace
C:\file\path\my_file.exeor/path/to/my_filewith the actual path to the file.
MacOS or Linux
From your preferred terminal application, run the following command:
openssl dgst -sha256 /path/to/my_file
Windows
Command Prompt
- Press
Windows+Rto open the Run box - Type
cmdand click OK. - The Command Prompt window will open.
- Run the following command:
certutil -hashfile C:\file\path\my_file.exe SHA256
Power Shell
- Press
Windows+Rto open the Run box - Type
powershelland click OK. - The Windows PowerShell window will open.
- Run the following command:
Get-FileHash C:\file\path\my_file.exe -Algorithm SHA256
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article