mechanism would need to be of the "remote code execution vulnerability"
and would represent a threat in many more use cases than when verifying
an ISO image.
Open questions
As the verification mechanism totally depends on the integrity of web
pages retrieved from our website and displayed to the user in their
browser, it would also be vulnerable to an attacker who could manage to
corrupt the verification mechanism or manipulate what is displayed to
the user **from inside the browser**. We are [still
whether such attacks are possible.
Checksum verification
