But no pgp verification? Where do you get the "good" checksum to compare against?
Discussion
Nm I'm an idiot and conflated checksum with hash. So no verification?
From Coinkite's official list of releases:
https://raw.githubusercontent.com/Coldcard/firmware/master/releases/signatures.txt
The PGP verification is done by the device itself.