Live data from Hacker News

Linux Mint downloads (briefly) compromised

lwn.net

31–40 of 236 posts

Re: Linux Mint downloads (briefly) compromised

#31
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

[deleted]

Re: Linux Mint downloads (briefly) compromised

#32
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

GPG signatures are kinda useless (when hosted on the same server). If I am able to replace the download I could probably deface also the pages where you give your signature and key fingerprint.

The point of GPG is to download the public key of the signer (in this case, the package maintainer). Then, you check it's bona fide, either by verifying that you have a trusted connection through your web of trust, or (more likely) by verifying the key id is mentioned in other trustworthy places (like legitimate Ansible and Bash scripts, etc.).

After that, you have a trusted signature, and it doesn't matter if it the signature page is defaced.

If you're downloading the signature each time you're downloading a new version of a package or iso, and its SHAs, you're using GPG incorrectly.

I've had many signatures for package signers in my keyring for 5+ years. If and when they replace the key, they let the community know and we update our keyrings.

Yes, if you don't want to do that, fine, but for those of us who are careful users of GPG, it's a huge barrier against malware in packages and distros.

Re: Linux Mint downloads (briefly) compromised

#33
post #3

Whos using Mint these days anyway ?

A lot of people according to http://distrowatch.com/dwres.php?resource=popularity . I was surprised to see Mint take the first spot.

I really don't see how distrowatch indicates anything, why would people using a system go to that site in particular? The latest wikimedia statistics from the middle of 2015 have:

* Linux Other 2,170 M 0.84%

* Linux Ubuntu 1,238 M 0.48%

* Linux Fedora 53.6 M 0.02%

* Mac PowerPC 49.7 M 0.02%

* Linux Mint 6.4 M 0.00%

* Linux Mips 4.6 M 0.00%

* Linux SUSE 3.9 M 0.00%

* Linux Debian 3.1 M 0.00%

etc

http://stats.wikimedia.org/wikimedia/squids/SquidReportOpera...

Re: Linux Mint downloads (briefly) compromised

#34
post #31
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

[deleted]

No consumer OS since Windows Me logs in with a system account by default.

Linux Mint sucks, but I'm pretty much OK with disabling autologin to root.

Re: Linux Mint downloads (briefly) compromised

#36
post #7
post #4

Earlier quoted context omitted.

I am not one, but lot's of people. Most switched off from Ubuntu, landed a stayed there.

I've found Xubuntu to be a pretty decent albeit simple environment. Runs great on my VM too.

Indeed. I never got why people are not just sticking with Xubuntu. It is the most solid, reliable, balanced and beautiful distro I have ever tried.

Everytime I tried something else, I finally came back to Xubuntu, and try to remind myself to never switch away again.

Re: Linux Mint downloads (briefly) compromised

#37
post #30

People I understand your criticism, but may I suggest donating to them too if you've used Mint? Once his bills are paid off, maybe he'll spend more time worrying about Mint?

Speaking for myself, I have donated multiple times to Mint.

> Once his bills are paid off

What bills are you talking about? As a result of this incident?

Re: Linux Mint downloads (briefly) compromised

#38

Every once in a while, I get difference error in /etc/issue*. I really hate all of these. I use Mint only because I like its GUI interface. I really cannot stand Ubuntu desktop for a moment

I also use Mint mostly because of its interface and i hate Ubuntu desktop too.

Given this, what are the best alternatives to Mint GUI that offer the same level of comfort?

Re: Linux Mint downloads (briefly) compromised

#39
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

GPG signatures are kinda useless (when hosted on the same server). If I am able to replace the download I could probably deface also the pages where you give your signature and key fingerprint.

APT can automatically verify GPG signatures against a preinstalled keyring. Obviously, that doesn't help in the case of this particular incident (ISOs), but it does help in day-to-day updates.

Re: Linux Mint downloads (briefly) compromised

#40
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

I'm curious- what do you think of Fedora? It's in the top 5 distros along with OpenSUSE, Ubuntu, Debian, and Mint, and yet I hardly ever hear people talk about it.

I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.

Post reply on HN