Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify Ubuntu Signatures inside Yeti Script (next release - not hotfix) #150

Open
JWWeatherman opened this issue Mar 22, 2021 · 1 comment
Assignees

Comments

@JWWeatherman
Copy link
Owner

Let's add a step early in setup where the user inserts their Ubuntu thumb drive and we verify the signatures of the download. This is usually done before installation, but the daily driver laptop they are using is arguably less trustworthy than the freshly installed ubuntu laptop where the installation was downloaded from a very well known and reputable URL and signatures are verified after the fact. And we can automate it.

@Rspigler
Copy link
Contributor

Hmm. This is tricky. A malicious version of Ubuntu could lie and say it is genuine, but like you said, their laptop is already assumed untrusted (daily laptop running proprietary OS). You ultimately can't verify something when starting from a possibly malicious source.

Technically, users should buy a fresh laptop to download/verify the ISO on, as well as a fresh laptop to install Ubuntu...

I guess I'm neutral on this since it is a large usability gain, and I'll still have verification instructions in the PDF

@Rspigler Rspigler mentioned this issue Mar 22, 2021
31 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants