Live data from Hacker News

Beware of hacked ISOs if you downloaded Linux Mint on February 20th

blog.linuxmint.com

61–62 of 62 posts

Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th

#61
post #59
post #58

Earlier quoted context omitted.

Because someone can do a man-in-the-middle attack and intercept the right hash and replace it with another one. And how do you verify that the public key is trusted for the first time?

I was under the impression that you can have your key signed by a generally trusted CA.

GPG has no central CAs, but relies on a "web of trust" situation. In reality, there's no one central that everyone trusts, so unless the keys are signed by some individual you personally trust, you're down to being reliant on getting valid keys.

Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th

#62
post #54

Earlier quoted context omitted.

Yo ryanlol, you made the press again except the pricks didn't mention your name: http://news.softpedia.com/news/linux-mint-website-hack-a-tim...

I think calling softpedia "press" is an insult to every real journalist. The fact that they're calling the bot "tsunami" just proves their incompetence. The bot isn't called tsunami, it's called kaiten and it's been open source for more than a decade. https://packetstormsecurity.com/files/25575/kaiten.c.html They also managed to confuse FTP and HTTP >the hackers have only altered the man.cy [ https://gist.github.com/…

>I neither bought nor sold the data.

Considering you're still on probation or whatever (I think?), is that really wise to say?

Post reply on HN