Joe Btfsplk writes:

> Is it really a risk, d/l  Tor or TBB directly from Tor Project's
> site, that verifying signatures is necessary?  What is the reasoning
> here - if getting files from Tor Project server?

How do you know it was really the Tor Project server?

