> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/notes-mcs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/notes-mcs/computer-systems-forensic-analysis/obtaining-evidences/hash-values.md).

# Hash Values

To guarantee integrity, hash values should be stored.

* Hash blocks of small size to prevent a single error to invalidate all drive images.
  * e.g. the same size as the acquisition block.
* In a RAW file; hash values are stored in a separate file.
* **It is always recommended to do a digital signature on the hash values files.**
  * Why do you think this is good practice?

Digital signatures.

* The best tool is [GnuPG](https://www.gnupg.org/).
* If possible, use also a time-stamping server.
