How can I cryptographically verify a sabayon.iso? Are there any certificates?
2
votes
1
answer
133
views
I've downloaded and installed sabayon, but all I can find to verify that iso image is an md5sum that can only be downloaded from the same insecure mirrors.
- md5 checksums are not cryptographically secure -- that should be at least sha256.
- the mirrors to download that checksum from use only insecure protocols (http, ftp, rsync), therefore can not be trusted.
- I can't find anything about security issues on Google (at least while I'm running sabayon). Is this distribution designed to pleasure hackers and supported by the NSA? (or am I paranoid?)
- would it be secure to install sabayon via gentoo-overlay? (or is there a similar but secure gentoo-based distro out there?)
Asked by comonad
(121 rep)
Apr 9, 2016, 12:36 PM
Last activity: Jun 24, 2018, 07:41 AM
Last activity: Jun 24, 2018, 07:41 AM