TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“Only the paranoid survive.” – Qubes OS signature mismatch

60 pointsby eluxover 8 years ago

9 comments

Gruselbauerover 8 years ago
Redownload. Check again. I&#x27;m on satellite internet with the horrible latencies and frequent timeouts associated with that tech, I recently had the netinstall image for Debian fail integrity checking three times in a row, from the http mirrors. Guy from the link said it himself, download via torrent and all is well.<p>Generally, being on such terrible interwebs I get angry whenever I hear people claim torrents are only for piracy. We all know they&#x27;re wrong, but my legal torrent use has really never been more intense. Rsync&#x27;s ability for aggressive retrying is also blessed :)
评论 #13101668 未加载
评论 #13101874 未加载
lwfover 8 years ago
There are a bunch of reasons this could&#x27;ve happened -- corrupted downloads are not unheard of on poor connections. Maybe the file was truncated.<p>Or maybe it was the NSA. Without any further analysis, this isn&#x27;t particularly noteworthy.
评论 #13101460 未加载
评论 #13101541 未加载
quickbenover 8 years ago
Seeking publicity instead of trying to redownload and verify.<p>News today, sigh :(
评论 #13101604 未加载
评论 #13101580 未加载
lillesvinover 8 years ago
There&#x27;s nothing yet to suggest that it&#x27;s not just a corrupted download.
评论 #13101942 未加载
trdtaylor1over 8 years ago
Best way to elevate your crypto project, get targeted. Doesn&#x27;t matter if it actually happened.
daveioover 8 years ago
Can&#x27;t speak to targeted interference, but I can fetch the ISO and signature from the mirror he used, and verify it successfully.<p>output: <a href="https:&#x2F;&#x2F;gist.github.com&#x2F;daveio&#x2F;edac4aaee516cd6a408d5c8e763cef5f" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;daveio&#x2F;edac4aaee516cd6a408d5c8e763ce...</a>
mockoover 8 years ago
For reference, here&#x27;s a check of the torrent with the .torrent file I snagged from <a href="https:&#x2F;&#x2F;www.qubes-os.org&#x2F;downloads&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.qubes-os.org&#x2F;downloads&#x2F;</a> last night. Master signing key checked against the fingerprint published on the mailing list in 2013. Looks legit.<p><pre><code> Qubes-R3.2-x86_64 moi$ gpg --verify Qubes-R3.2-x86_64.iso.asc Qubes-R3.2-x86_64.iso gpg: Signature made Tue Sep 20 18:33:37 2016 BST using RSA key ID 03FA5082 gpg: Good signature from &quot;Qubes OS Release 3 Signing Key&quot; [full]</code></pre>
评论 #13101813 未加载
imjustsayingover 8 years ago
when did download errors become newsworthy? are networks that robust now?
loegover 8 years ago
Probably just truncated.