5 ms·
Counter-example: Ubuntu serves their ISO via an HTTP link on an HTTPS page. They supply a gpg signature as a way to validate that the file was not tampered with
by kemitche 8y ago
Counter-example: Ubuntu serves their ISO via an HTTP link on an HTTPS page. They supply a gpg signature as a way to validate that the file was not tampered with.
- mfoy_ 8y agoWhy? Why not serve the ISO over HTTPS?
- sneak 8y agoThe hostname resolves to a bunch of different mirrors run by different people who don’t all share a secret key between them. There are workarounds for this (using a redirector service and unique hostnames) but that is an additional request of donors who are providing them a lot of bandwidth for free. It’s not a great reason, but it is a reason.
- floatingatoll 8y agoISO files are not considered a common (if not most common) vector for malware delivery. While it’s dumb that they serve it over HTTP (don’t use CNAME-based mirror setups, everyone) it’s also neither putting anyone at significant risk to allow it nor under consideration for blocking.