Linux Mint ISO was compromised.

Status
Not open for further replies.
Originally Posted By: StorminNorvin
Originally Posted By: uc50ic4more
Then why not Mint's MATE version? It's been around a while longer and has had a lot more attention given it over the years.

I hate the layout. I also hate the fact that to update the kernel, you have to do it in Terminal instead of the Software Updater. Still, I hate the layout.


Point(s) well taken. This most recent SNAFU for Mint also underscores the disadvantages of being a small team without the resources Canonical has.
 
I don't have a deep understanding of how torrents work, just some surface knowledge.

What would prevent someone from seeding a compromised ISO via a torrent?

Originally Posted By: uc50ic4more
Originally Posted By: JGmazda
And I've learned to always check the MD5 checksums:

http://www.everydaylinuxuser.com/2016/02/this-is-very-important-check-your-iso.html


Hackers just change those as well. Using the torrents instead of downloading directly from the provider's server is safest. (And it saves bandwidth for the provider.)
 
Originally Posted By: javacontour
What would prevent someone from seeding a compromised ISO via a torrent?


Nothing. But they'd have a difficult time supplanting the thousands of already-existing ISO's being seeded by legitimate users *and* the checksums wouldn't work out relative to the proper ISO's either so they couldn't be spoofed. A hacker could compromise the one ISO on the Mint server all they want; but when getting the file over BitTorrent you're grabbing it from a large number of unrelated, private individuals who have a good copy.

The only thing that one needs to understand about torrents to understand why they're safer for distribution is that torrents are entirely de-centralized.

I once read a (half) joke on Slashdot in response to someone concerning themselves over long-term backup of sensitive data: It was suggested that they encrypt an archive of their data, name the TAR file Jessica_Alba_Nude.mp4 and seed it on The Pirate Bay. There'd be several hundred thousand copies of your encrypted data floating around the interwebs; and if/ when you ever needed it again you'd be able to download it again quickly!
 
I guess I could see a scenario where they posted the same compromised ISO as they put on the site. For some time period, their ISO would match the one on the Mint server, check-sums and all.

It's one of those which is the evil twin scenarios. That is, if anyone happened to notice that there was more than one torrent out there. Even if they did, which check-sum would they trust? Would they trust the torrent that matches the compromised website, or the one that in essence says, trust us, this is the real one even though it doesn't match?


Originally Posted By: uc50ic4more
Originally Posted By: javacontour
What would prevent someone from seeding a compromised ISO via a torrent?


Nothing. But they'd have a difficult time supplanting the thousands of already-existing ISO's being seeded by legitimate users *and* the checksums wouldn't work out relative to the proper ISO's either so they couldn't be spoofed. A hacker could compromise the one ISO on the Mint server all they want; but when getting the file over BitTorrent you're grabbing it from a large number of unrelated, private individuals who have a good copy.

The only thing that one needs to understand about torrents to understand why they're safer for distribution is that torrents are entirely de-centralized.

I once read a (half) joke on Slashdot in response to someone concerning themselves over long-term backup of sensitive data: It was suggested that they encrypt an archive of their data, name the TAR file Jessica_Alba_Nude.mp4 and seed it on The Pirate Bay. There'd be several hundred thousand copies of your encrypted data floating around the interwebs; and if/ when you ever needed it again you'd be able to download it again quickly!
 
Even if a hacker could replace an ISO in a torrent, that singular copy would be the only seed and the swarm would be slowed to a crawl. The instant the proper ISO were restored then the checksums would be again out of whack and the downloads of the hacked copy would themselves fail. Widespread propagation, decentralization and distributed hash tables make distributing malware via torrent tough sleddin'.
 
Perhaps we are missing one another.

I'm not talking of seeding it in the same torrent, but a whole new torrent.

How do you know which is the authentic torrent if the hacker already posted the corrupt ISO and it's check-sum on the compromised site?

Who is to say the hacker with access doesn't post the torrent on the site since it's already compromised?

Originally Posted By: uc50ic4more
Even if a hacker could replace an ISO in a torrent, that singular copy would be the only seed and the swarm would be slowed to a crawl. The instant the proper ISO were restored then the checksums would be again out of whack and the downloads of the hacked copy would themselves fail. Widespread propagation, decentralization and distributed hash tables make distributing malware via torrent tough sleddin'.
 
Status
Not open for further replies.
Back
Top Bottom