Seeking publicity instead of trying to redownload and verify. News today, sigh :(
“Only the paranoid survive.” – Qubes OS signature mismatch
11–20 of 24 posts
Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#12Seeking publicity instead of trying to redownload and verify. News today, sigh :(
At best, it's unfiltered information, and usually just noise and venting.
Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#13Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#14 Qubes-R3.2-x86_64 moi$ gpg --verify Qubes-R3.2-x86_64.iso.asc Qubes-R3.2-x86_64.iso
gpg: Signature made Tue Sep 20 18:33:37 2016 BST using RSA key ID 03FA5082
gpg: Good signature from "Qubes OS Release 3 Signing Key" [full]Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#15Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#16Redownload. Check again. I'm on satellite internet with the horrible latencies and frequent timeouts associated with that tech, I recently had the netinstall image for Debian fail integrity checking three times in a row, from the http mirrors. Guy from the link said it himself, download via torrent and all is well. Generally, being on such terrible interwebs I get angry whenever I hear people claim torrents are only…
Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#17Redownload. Check again. I'm on satellite internet with the horrible latencies and frequent timeouts associated with that tech, I recently had the netinstall image for Debian fail integrity checking three times in a row, from the http mirrors. Guy from the link said it himself, download via torrent and all is well. Generally, being on such terrible interwebs I get angry whenever I hear people claim torrents are only…
Yea that's one thing I really love about torrents. Because of the giant set of hashes they use, it makes it really great to verify integrity of the download. You've got a hash for each block (128k by default) and for the overall download, along with the complete size of the file.
Depends on the seed creation software, Tixati defaults to 256k for instance, kind-of: it's the default value of the box, but a new default is recomputed based on the amount of data included in the torrent. If I try to seed my local install of Bastion (920MB) it picks 1MB, Atom Zombie Smasher (25MB) yields 64kB, and Shadowrun Hong Kong (9GB) picks 4MB.
Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#18For reference, here's a check of the torrent with the .torrent file I snagged from https://www.qubes-os.org/downloads/ last night. Master signing key checked against the fingerprint published on the mailing list in 2013. Looks legit. Qubes-R3.2-x86_64 moi$ gpg --verify Qubes-R3.2-x86_64.iso.asc Qubes-R3.2-x86_64.iso gpg: Signature made Tue Sep 20 18:33:37 2016 BST using RSA key ID 03FA5082 gpg: Good signature from "Q…
Qubes-R3.2-x86_64 moi$ gpg --verify Qubes-R3.2-x86_64.iso.asc Qubes-R3.2-x86_64.iso_WEBDL
gpg: Signature made Tue Sep 20 18:33:37 2016 BST using RSA key ID 03FA5082
gpg: Good signature from "Qubes OS Release 3 Signing Key" [full]
Of course (skipping merrily off into tinfoil-hat-land) that doesn't eliminate the possibility that the OP's download had been MITM-ed. However this would have to be by someone who:1) Controls part of the network infrastructure between them and mirrors.kernel.org (i.e. routers, cables or DNS)
2) Can fake a TLS certificate for mirrors.kernel.org
So, corrupted download or a targeted MITM attack by a state-level actor? Who the hell knows anymore.
Re: “Only the paranoid survive.” – Qubes OS signature mismatch
#19Redownload. Check again. I'm on satellite internet with the horrible latencies and frequent timeouts associated with that tech, I recently had the netinstall image for Debian fail integrity checking three times in a row, from the http mirrors. Guy from the link said it himself, download via torrent and all is well. Generally, being on such terrible interwebs I get angry whenever I hear people claim torrents are only…
Debian supports using HTTPS mirrors.