Live data from Hacker News

Linux Mint downloads (briefly) compromised

lwn.net

91–100 of 236 posts

Re: Linux Mint downloads (briefly) compromised

#91

Earlier quoted context omitted.

GPG signatures are kinda useless (when hosted on the same server). If I am able to replace the download I could probably deface also the pages where you give your signature and key fingerprint.

APT can automatically verify GPG signatures against a preinstalled keyring. Obviously, that doesn't help in the case of this particular incident (ISOs), but it does help in day-to-day updates.

Not sure why this was downvoted, since it's true. apt does this by default, in fact.

GPG is immensely useful for securely distributing packages and distros.

Re: Linux Mint downloads (briefly) compromised

#92

Earlier quoted context omitted.

A lot of people according to http://distrowatch.com/dwres.php?resource=popularity . I was surprised to see Mint take the first spot.

I really don't see how distrowatch indicates anything, why would people using a system go to that site in particular? The latest wikimedia statistics from the middle of 2015 have: * Linux Other 2,170 M 0.84% * Linux Ubuntu 1,238 M 0.48% * Linux Fedora 53.6 M 0.02% * Mac PowerPC 49.7 M 0.02% * Linux Mint 6.4 M 0.00% * Linux Mips 4.6 M 0.00% * Linux SUSE 3.9 M 0.00% * Linux Debian 3.1 M 0.00% etc http://stats.wikimedia…

Indeed I never considered better sources.

Re: Linux Mint downloads (briefly) compromised

#93
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

Have you given Arch a try yet? Their are also some family friendly projects like Antergos. Arch wiki is my all time favorite for great documentation, even when not using arch, go figure.

The documentation is good, I'm using it to configure KVM on Fedora now.

Re: Linux Mint downloads (briefly) compromised

#94
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

Have you given Arch a try yet? Their are also some family friendly projects like Antergos. Arch wiki is my all time favorite for great documentation, even when not using arch, go figure.

Personally, I wouldn't recommend Arch (even the "friendly" variants like Antergos) to the less technically inclined. You don't need a to be extremely familiar with Linux to get started with Arch, but you do need to be comfortable at the command line and are expected to be able to read the (excellent) docs and debug things yourself.

It's a very educational experience, but not really something the "average grandmother" is likely to have the patience for, particularly when they're just trying to watch a flash video on Facebook. That's the real strength of Mint, and I'm not sure what best fills that niche if Mint is off the table.

Re: Linux Mint downloads (briefly) compromised

#95
post #53

Earlier quoted context omitted.

> "ok, US users can't get this, but everyone else can" Setting aside for a minute that this isn't possible, it's like saying you won't release your app on iOS because of Apple's walled gardens. Sure, the walls suck, but the users inside are numerous and spend lots of money. Most product creators don't have the option to exclude US users.

Not everyone is entirely driven by money, I choose not to write software for any of the walled gardens.

Wait, so you avoid walled gardens by...exercising your right to include proprietary plugins in software?

Re: Linux Mint downloads (briefly) compromised

#97
post #59

Earlier quoted context omitted.

Check out NixOS

I absolutely love the concept of NixOS, but I haven't tried it out. Is it well-supported enough to use day-to-day as a developer? Do you often have to build things from source?

> Is it well-supported enough to use day-to-day as a developer?

Speaking as someone who knows the developer: no.

> Do you often have to build things from source?

There's ~6500 packages, so it's likely you'll be installing some stuff from source. It's really hard to predict without knowing specifics though. http://hydra.nixos.org/eval/1237359

Re: Linux Mint downloads (briefly) compromised

#98
post #24

I remember installing it when it was relatively new and people were gushing over it. A few weeks later a new version came out. I tried upgrading when I found there was no upgrade path. Upgrading Mint means reinstalling Mint. I remember the days before apt-get when there was only dpkg. Before Debian I used Slackware so I'm all too familiar with package management (or lack of). The idea that someone would release a new…

"why it needs its own distribution" Because....Linux ? Seriously, in theory in Linux you should be able to mix and match any DE with any windows manager. In practice it doesn't work like that at all.

Modularity has its price.

Re: Linux Mint downloads (briefly) compromised

#99
As a super happy user of Linux Mint - guys, please keep doing what you are doing! Thank you so much for giving us a proper desktop Linux! You have my (financial) support! Don't get pressured by some random loud Internet criticism and change for worse! Please don't do Win7->Win8 or iOS6->iOS7 regression in Mint as well because of a few unhappy voices trying to acquire power over you!
Post reply on HN