Skip to content

Verifying Downloads

Riqqqque edited this page Oct 3, 2026 · 1 revision

Verifying Downloads

Flashback runs next to your games all day, so it's worth a minute to make sure the installer you downloaded is the genuine one. This page shows the two checks: the SHA-256 hash, which proves the file is byte-for-byte the official release, and the digital signature, which shows who published it.

Download only from official places

Source Notes
flashbk.gg The Download button always points at the current release.
This repository's Releases page Each Flashback release is an immutable tag that's never changed after publishing.

Current releases (0.6.74 and later) contain exactly two files:

  • Flashback-Setup-<version>.exe, the installer.
  • SHA256SUMS.txt, the SHA-256 hash of that installer.

GitHub also lists Source code (zip) and Source code (tar.gz) on every release. Those are generated by GitHub from this repository, which holds only a README; they don't contain Flashback. Separate releases tagged ffmpeg-... hold the corresponding source of Flashback's FFmpeg build, not an app installer.

Don't run Flashback installers from other sites, re-uploads or "mirrors". They can't be checked against the official hash, and you have no way to know what's inside.

Check 1: the SHA-256 hash

A SHA-256 hash is a fingerprint of the file's exact bytes. If even one byte differs, the hash is completely different.

  1. Open PowerShell (press Start, type PowerShell, press Enter).

  2. Run this, replacing <version> with the version you downloaded:

    Get-FileHash "$env:USERPROFILE\Downloads\Flashback-Setup-<version>.exe" -Algorithm SHA256
  3. Compare the Hash it prints with either:

    • the line for that file in the release's SHA256SUMS.txt, or
    • the SHA-256 shown on flashbk.gg/faq.

They must match exactly. PowerShell prints the hash in capital letters and SHA256SUMS.txt may use lowercase; that difference doesn't matter, but every character must be the same.

Prefer the Command Prompt? certutil -hashfile Flashback-Setup-<version>.exe SHA256 prints the same hash.

The hash is the decisive check. If it matches the published value, you have the official file.

Check 2: the digital signature

Flashback's installer and program files are signed through Microsoft Artifact Signing.

  1. Right-click the installer and choose Properties.
  2. Open the Digital Signatures tab. (If the tab is missing, the file isn't signed: don't run it.)
  3. Select the signature and choose Details. Windows should say This digital signature is OK, and the signer should be a named, verified publisher rather than "Unknown publisher".

You can do the same in PowerShell:

Get-AuthenticodeSignature "$env:USERPROFILE\Downloads\Flashback-Setup-<version>.exe" | Format-List Status, SignerCertificate

Status should read Valid.

Signing certificates from Microsoft's service are short-lived and renewed often, so the certificate on one release differs from the next. That's normal. Each signature is timestamped, so it stays valid after the certificate itself expires.

If Windows SmartScreen asks first

Because Flashback's signing certificate is new, Windows SmartScreen may still show Windows protected your PC for a while as the download builds reputation. That's a reputation prompt, not a signing fault.

  1. Click More info.
  2. Check that the Publisher line names a verified publisher, not "Unknown publisher".
  3. Click Run anyway.

If the publisher is missing, or the hash doesn't match, don't run the file. Delete it and download again from flashbk.gg.

If something doesn't match

  • Download again from flashbk.gg. A download interrupted by your browser or antivirus can be incomplete.
  • Check the version. The hash belongs to one exact version. Make sure you're comparing against the SHA256SUMS.txt from the same release, or the FAQ when it shows that version.
  • Still different? Don't run it, and tell us through the support form with the Security type.

Updates check themselves

You only need to do this for installers you download yourself. Updates installed from inside Flashback are checked automatically against two independent signatures, the exact package hash and the pinned publisher before anything is installed. See Update Security Chain.

Related pages

Getting Started · Installing and Updating · Security · Update Security Chain

Clone this wiki locally