I'm aware now that file download verification have been widely implemented. However, verification detail permananetly published on the website is still not safe. As far as I know, md5 checksum and other digital signature can also be hacked. I'm wondering if it is possible for IT people to generate md5 checksum online of which Nero's approch is improvable - try to visit
http://www.nero.com/ena/downloads-linux3-trial.php
For the time being, every time one puts email in the box, the page is just generate the same md5 checksum. How easy is it to generate different one using the same mode?
Could another approach be to use double digital signatures with different application clients?