Live data from Hacker News

Linux Mint downloads (briefly) compromised

lwn.net

61–70 of 236 posts

Re: Linux Mint downloads (briefly) compromised

#61

Starting a post with "I know this is voluntary work, pitch in or shut up and all that ..." doesn't make the quote you're attacking untrue. For what I'm paying for Mint ($0.00) and what I get out of it in terms of productivity, I find it quite a decent distribution.

If Mint advertised, "Free to download, but also free of good security practices", then I could buy this argument.

The problem is that Mint allows users to trust it. It would be better if they didn't work on the distro at all if they're not going to take security seriously.

People on HN become furious about antivirus programs and routers and whatever else that are discovered to be laughably insecure. An OS is no less of security product than A/V or a router. In fact, it's the first line of defense for an end user.

Re: Linux Mint downloads (briefly) compromised

#62
post #32

Earlier quoted context omitted.

The point of GPG is to download the public key of the signer (in this case, the package maintainer). Then, you check it's bona fide, either by verifying that you have a trusted connection through your web of trust, or (more likely) by verifying the key id is mentioned in other trustworthy places (like legitimate Ansible and Bash scripts, etc.). After that, you have a trusted signature, and it doesn't matter if it the…

I am first time linux mint user. The only place I can find who the developers are/what keys are used/signed and so on is their (compromised) site. Once we have established trust it is easy to maintain it.

True, but the site has to be compromised at the moment you are downloading the keys (not anytime later!), and then all your further installations have to me MITM-ed or you would take notice. Not so trivial for attacker anymore.

Ideally, the keys should be distributed in safe fashion too, so this whole question should be moot.

Re: Linux Mint downloads (briefly) compromised

#63
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

I'm curious- what do you think of Fedora? It's in the top 5 distros along with OpenSUSE, Ubuntu, Debian, and Mint, and yet I hardly ever hear people talk about it. I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.

Fedora has come a long way from where it came from. It is much better then it used to be and has become really fast, secure, and yes: user-friendly.

I use Fedora @work and Ubuntu @home. The reason I use Ubuntu @home is that my roommates run Ubuntu too and we get all the same Versions on whatever software.

But @work I run Fedora. There aren't any particular reasons except that it just "feels" better to work on that on Ubuntu. I definitely recommend to give it a try.

Using something like Fedy or easyLife makes setting up Fedora fun and fast.

https://github.com/folkswithhats/fedy

http://easylifeproject.org/

Re: Linux Mint downloads (briefly) compromised

#64
post #45

Earlier quoted context omitted.

I'm curious- what do you think of Fedora? It's in the top 5 distros along with OpenSUSE, Ubuntu, Debian, and Mint, and yet I hardly ever hear people talk about it. I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.

Fedora's latest release rocks. Fedora used to have stability issues here or there because it's the cutting-edge version of RHEL, but I think it's unlikely you'd run into those in everyday usage with mainstream hardware. It shouldn't be less stable than Ubuntu.

Is the recommended way to switch between major versions of Fedora still to wipe and reinstall?

For a long time back in the early teen releases there were no sane upgrade paths which pushed me to Debian.

Re: Linux Mint downloads (briefly) compromised

#65
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

I'm curious- what do you think of Fedora? It's in the top 5 distros along with OpenSUSE, Ubuntu, Debian, and Mint, and yet I hardly ever hear people talk about it. I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.

Don't want to be that evangelist guy BUT OpenSUSE really deserves a second looks and it is non-technical family member friendly. They are super stable and provide one-click install off the web like Mint, but it install them as a regular repo which makes updating them a breeze.

On the technical I love OpenSUSE for zypper, build (Any software you need is probably on there and it will even build for other distros), rolling releases in Tumbleweed, and the best KDE default environment for over a decade..

Re: Linux Mint downloads (briefly) compromised

#66
post #50
post #19

> Add to that, that they do not care about copyright and license issues and just ship their ISOs with pre-installed Oracle Java and Adobe Flash packages and several multimedia codec packages which infringe patents and may therefore not be distributed freely at all in countries like the US. Hmm, that was actually one of major selling points for Mint around me - it was the distro that "worked", with relevant software,…

It's user friendly, yes, but also reckless. The distro won't "work" any more if it gets sued into oblivion by Oracle, Adobe, Nvidia, AMD and whoever else feels like kicking puppies.

The flip side is that if you believe that laws like those around software patents should change, someone ignoring them and taking the risk of being sued is a more compelling demonstration than carefully observing the rules and then complaining about them on HN.

More pragmatically, it seems unlikely that Oracle or Adobe will sue a distro for helping them distribute the Java/Flash runtimes. They want their runtime to be on as many devices as possible.

Re: Linux Mint downloads (briefly) compromised

#67
post #64
post #45

Earlier quoted context omitted.

Fedora's latest release rocks. Fedora used to have stability issues here or there because it's the cutting-edge version of RHEL, but I think it's unlikely you'd run into those in everyday usage with mainstream hardware. It shouldn't be less stable than Ubuntu.

Is the recommended way to switch between major versions of Fedora still to wipe and reinstall? For a long time back in the early teen releases there were no sane upgrade paths which pushed me to Debian.

No, there are now fully integrated system update tools that handle this smoothly.

Re: Linux Mint downloads (briefly) compromised

#68
post #44

Earlier quoted context omitted.

I'm curious- what do you think of Fedora? It's in the top 5 distros along with OpenSUSE, Ubuntu, Debian, and Mint, and yet I hardly ever hear people talk about it. I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.

Fedora isn't for non technical family members. Here's a bit of mild whinging that's only relevant if you want to give it to non-technical people. There's a move to give stuff generic names, rather than the obscure names they had in the past. For example, Nautilus has been renamed to Gnome Files, or just Files. When a non technical person needs to search for hep this new name makes it impossible for them to create a u…

> For example, Nautilus has been renamed to Gnome Files, or just Files.

It's a bad trend. It's really frustrating when you're trying to find out what the executable or package name is.

Re: Linux Mint downloads (briefly) compromised

#69
post #3

Whos using Mint these days anyway ?

The poor saps who have it recommended to them or installed for them.

It's a desktop environment theme at best, and could be packaged as such. Maintaining a distro for general consumption (it's pitched to new users as "Windows like"), is very hard work and carries a lot of responsibility.

Post reply on HN