install an OS? There's always some chain of trust. Not only you have to trust whoever created the distro you're installing, but also you need to make sure there's no MitM. All sane distros provide checksums and pgp signatures, but they are stored in the same location as the iso. So if there is a MitM you wouldn't know because he would have given you other checksums and signatures so that the match a malicious version of the distro. It could go as far as your ISP intercepting your DNS and providing you the malicious website. Yeah you verify that with TLS certificate, but then you rely on CAs and on the fact that your current distribution which you used to download and check the image has no malicious code that would replace CAs for example or replace programs for checksums and gpg to display "OK" when you download a malicious copy...
Well you also need to be paranoid when doing everything else online then
Yeah, which is why I don't trust mint
Обсуждают сегодня