LWN.net Logo

Study: Attacks on package managers

Study: Attacks on package managers

Posted Jul 16, 2008 18:17 UTC (Wed) by MattPerry (guest, #46341)
In reply to: Study: Attacks on package managers by MattPerry
Parent article: Study: Attacks on package managers

Today I'm getting this error:

GPG error: http://security.ubuntu.com hardy-security Release: The following signatures were invalid: BADSIG 40976EAF437D05B5 Ubuntu Archive Automatic Signing Key <ftpmaster@ubuntu.com>Failed to fetch http://us.archive.ubuntu.com/ubuntu/dists/hardy-updates/main/binary-i386/Packages.bz2 Hash Sum mismatch

Some index files failed to download, they have been ignored, or old ones used instead.

If I try to move ahead and installed I get a bold warning that packages can't be authenticated. No suggestions are provided on how to fix the problem. I don't know what I can do except back up my files and reinstall Ubuntu.


(Log in to post comments)

Study: Attacks on package managers

Posted Jul 21, 2008 9:35 UTC (Mon) by mdz@debian.org (subscriber, #14112) [Link]

This is typically due to a broken transparent proxy, or similar network anomaly, between you
and your chosen package mirror.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds