5 ms·
No you are not. the "bug" is that the download page has a link to an http mirror. If there was a bug where the ubuntu website could force your browser to displ
by SpaceNugget 7y ago
No you are not. the "bug" is that the download page has a link to an http mirror.
If there was a bug where the ubuntu website could force your browser to display https:// https:// and serve content over http without a warning you would have most definitely heard about it before now.
As to why most mirrors serve over http, it's for the same reasons presented here: https://whydoesaptnotusehttps.com/ https://whydoesaptnotusehttps.com/
- ben_w 7y agoIs there any clear reason why the checksums are also only available on http domains? One of the duplicate bugs: https://bugs.launchpad.net/ubuntu-website-content/+bug/1534967 https://bugs.launchpad.net/ubuntu-website-content/+bug/15349... I believe your link does not explain why Ubuntu’s .iso files are not on https, as one of its justifications is that APT uses other mechanisms for integrity checking, which doesn’t apply to OS installation disk images.
- dontbenebby 7y agoI agree with parent, it doesn't make sense to host checksums on a plain HTTP site. Also grandparent's link states >HTTPS does not provide meaningful privacy for obtaining packages. As an eavesdropper can usually see which hosts you are contacting Which is untrue. An attacker can't tell which specific packages are being downloaded, which could be important depending on your threat model. (The argument can be made size of DL leaks info, but that's a lot of work, and multiple packages could have same size)