3 ms·
And where did you get the reference SHA256SUMS from ? Did you check the gpg signature on them against a good sig from somewhere?
by trebligdivad 1y ago
And where did you get the reference SHA256SUMS from ? Did you check the gpg signature on them against a good sig from somewhere?
- tuhgdetzhh 1y agoGood Point. The checksums posted on Xubuntu.org could also compromised.
- diogenes_atx 1y agoI downloaded the checksums and the ISO image from the Xubuntu website: https://mirror.us.leaseweb.net/ubuntu-cdimage/xubuntu/releases/24.04/release/ https://mirror.us.leaseweb.net/ubuntu-cdimage/xubuntu/releas... This url is on the main Xubuntu website, under "Xubuntu 24.04": click "Release page," then select United States. From there, you download the following files: SHA256SUMS, SHA256SUMS.gpg, xubuntu-24.04.3-desktop-amd64.iso The output of the other checksum commands is shown here: [user@host]$ gpg --keyid-format long --verify SHA256SUMS.gpg SHA256SUMS gpg: Signature made Thu 07 Aug 2025 06:05:22 AM CDT gpg: using RSA key 843938DF228D22F7B3742BC0D94AA3F0EFE21092 gpg: Can't check signature: No public key [user@host]$ sha256sum --check SHA256SUMS xubuntu-24.04.3-desktop-amd64.iso: OK (output omitted for results of Xubuntu minimal version, which was not downloaded) The checksum is a cryptographic hash generated from the ISO file's contents. While the checksum for a specific, unchanged ISO file is fixed, the checksum that is published on a website could be deliberately altered by an attacker to hide a modified, malicious ISO.
- ntoskrnl_exe 1y agoAccording to the SHA256SUMS from Canonical's official download page at https://cdimage.ubuntu.com/xubuntu/releases/24.04.3/release/ https://cdimage.ubuntu.com/xubuntu/releases/24.04.3/release/ that is the correct checksum.
- ranger_danger 1y agohow does one know any signature they find is "good"?
- SV_BubbleTime 1y agoWe are in a perpetual loop of inefficient check methods, a bunch of steps, rediscovering what a supply chain attack is, a bunch of steps and just loop back over again.
- _def 1y agoGenerally speaking, a signature is cryptographically signed, when a checksum value is encrypted with the owners private key. The according public key should ideally be distributed in a chain-of-trust, so it can be obtained through a trusted channel.
- kwk1 1y agoIf you're using a Debian derivative these keys should be in packages distributed with your distro with trust coming from that
- SAI_Peregrinus 1y agoSince the distro's site was compromised you also have to check that any keys it distributes haven't changed. And that the compromise wasn't done by a legitimate maintainer.
- kwk1 1y agoThe packages in question don't come from the distro's homepage.