An Empirical Study of the Usage of Checksums for Web Downloads
Gaël Bernard, Rémi Coudert, Bertil Chapuis, Kévin Huguenin
Abstract
Checksums, typically provided on webpages and generated from cryptographic hash functions (e.g., MD5, SHA256) or signature schemes (e.g., PGP), are commonly used on websites to enable users to verify that the files they download have not been tampered with when stored on possibly untrusted servers. In this paper, we elucidate the current practices regarding the usage of checksums for web downloads (hash functions used, visibility and validity of checksums, type of websites and files, etc.), as this has been mostly overlooked so far. Using a snowball-sampling strategy for the 200,000 most popular domains of the Web, we first crawled a dataset of 8.5M webpages, from which we built, through an activelearning approach, a unique dataset of 277 diverse webpages that contain checksums. Our analysis of these webpages reveals interesting findings about the usage of checksums. For instance, it shows that checksums are used mostly to verify program files, that weak hash functions are frequently used, and that a non-negligible proportion of the checksums provided on webpages do not match that of their associated files. Finally, we complement our analysis with a survey of the webmasters of the considered webpages (𝑁 = 26), thus shedding light on the reasons behind the checksum-related choices they make. CCS CONCEPTS • Security and privacy → Web protocol security; Hash functions and message authentication codes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d187216b-49d1-4693-9e73-2db879fa3b46Builds on5
- An Empirical Study of Textual Key-Fingerprint RepresentationsSergej Dechand, Dominik Schürmann, Karoline Busse, Yasemin Acar et al.USENIX Security 2016 · 65 citations
- An Empirical Study of the Use of Integrity Verification Mechanisms for Web SubresourcesBertil Chapuis, Olamide Omolola, Mauro Cherubini, Mathias Humbert et al.WWW 2020 · 13 citations
- Towards Usable Checksums: Automating the Integrity Verification of Web Downloads for the MassesMauro Cherubini, Alexandre Meylan, Bertil Chapuis, Mathias Humbert et al.CCS 2018 · 11 citations
- Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRIMarius Steffens, Marius Musch, Martin Johns, Ben StockNDSS 2021
- CV-Inspector: Towards Automating Detection of Adblock CircumventionHieu Le, Athina Markopoulou, Zubair ShafiqNDSS 2021
Related papers
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 114 citations
- The More Things Change, the More They Stay the Same: Integrity of Modern JavaScriptJohnny So, Michael Ferdman, Nick NikiforakisWWW 2023 · 7 citations
- On the Security of SSH Client SignaturesFabian Bäumer, Marcus Brinkmann, Maximilian Radoy, Jörg Schwenk et al.CCS 2025
- Out of Sight, Out of Mind: Detecting Orphaned Web Pages at Internet-ScaleStijn Pletinckx, Kevin Borgolte, Tobias FiebigCCS 2021 · 11 citations
- Measuring Website Password Creation Policies At ScaleSuood Alroomi, Frank LiCCS 2023 · 15 citations
