Live data from Hacker News

Beware of hacked ISOs if you downloaded Linux Mint on February 20th

blog.linuxmint.com

1–10 of 62 posts

Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th

#4
post #3

Does anyone know the start date ? I had a friend install it for their laptop two weeks ago

>We were exposed to an intrusion today.

> [...]

>Finally, the situation both happened and was solved today, so it should only impact people who downloaded this edition on February 20th.

Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th

#7
post #6

Well that is scary. I personally don't check ISO checksums and signatures very often. Probably the only time I do is when I sometimes get install errors and wonder if I got all the bits and if anything got corrupted.

> don't check ISO checksums

I've grown obsessive about it. When you're conscious about that it's amazing (to put mildly) how many prominent projects don't bother with any authentication.

Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th

#8
I am pretty sad they're posting MD5 sums of the correct images: It's pretty trivial to collide MD5 -- and when you've got an active attacker, this is something you should worry about.

SHA1/2 at least, but preferably a gpg signature would be much better.

Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th

#9
post #6

Well that is scary. I personally don't check ISO checksums and signatures very often. Probably the only time I do is when I sometimes get install errors and wonder if I got all the bits and if anything got corrupted.

If they managed to hack the site to point to the new iso, they probably also changed any checksums. Signatures help, if you have a way to verify that you are using the right key.
Post reply on HN