Downloading
sha256sums.txt- downloading one or more signatures
- the archive itself
Then verifying each signature one by one. Then creating the sha256 of the archive. Then looking into the sha256sums.txt file if the sha256 sum matches. These are a lot steps. Kinda more cumbersome than verifying TBB 2.x (where you just verify the archive with a signature).
Can the required steps be reduced a bit without sacrificing security? Is shasums --check helpful?
If you want, feel free to edit this question and make it Linux/CLI specific if its too broad.
/distof the Tor site. – Oct 24 '13 at 12:46