Linux Mint downloads (briefly) compromised
Linux Mint downloads (briefly) compromised
Posted Feb 21, 2016 18:51 UTC (Sun) by job (guest, #670)Parent article: Linux Mint downloads (briefly) compromised
From the comments:
it seems like the download pages still point to the hacked ISOs.
[...]
this is a second attack so it means we’re still vulnerable
I am lost for words.
I know this is voluntary work, pitch in or shut up and all that, but that right there is just bad Internet citizenship beyond imagination. Both Fedora and Debian has had breaches. As soon as they were known all systems were immediately taken offline until all details had been worked out, to avoid repeat compromise, then completely re-imaged from scratch before they were put back online. The post mortem were then shared with the world to learn from. Nothing unusual, but best practice.
It's not very straightforward for their users to verify the integrity of the downloads. If you know were to look, there are signed hashes, but there is no trust path published for their keys. Those are solved problems. Again, just do what Debian and Fedora does. Why do we constantly need to re-invent this particular wheel?
