Securely downloading Ubuntu
Chris Lamb
chris at chris-lamb.co.uk
Fri Jan 25 00:42:19 UTC 2008
Hi,
Is it actually possible to securely download Ubuntu?
A typical mirror contains an MD5SUMS and an associated MD5SUMS.gpg [0].
However, the MD5 digest algorithm is utterly broken and the key is signed
by just a handful of people anyway[1], only two of which I (visually)
recognise as having anything to do with the Ubuntu project.
If the MD5SUMS files are purely for validating downloads[2], could the
completely useless/misleading GPG files be dropped?
/Lamby
[0] http://cdimage.ubuntu.com/releases/7.10/release/
[1] http://preview.tinyurl.com/2llzqr
[2] https://help.ubuntu.com/community/VerifyIsoHowto
--
Chris Lamb, UK chris at chris-lamb.co.uk
GPG: 0x634F9A20
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/ubuntu-devel-discuss/attachments/20080125/6c26038b/attachment.sig>
More information about the Ubuntu-devel-discuss
mailing list