Installing Linux: Am I paranoid or responsible?

For me, it’s not enough to verify the integrity of an ISO – I also have to verify its authenticity (or at least verify the checksum file) with GPG. I don’t know why, but just need to see that “Good signature” message before I feel safe installing Linux.

I notice, though, that the download pages of some prominent distros (Pop_OS!, openSUSE, etc) just give you a checksum, probably because they feel that anything else is unnecessary. This makes me shy away from installing them, which is a shame because I’d like to give some of those distros a try on bare metal.

Am I being paranoid when it comes to installing Linux?

MrAlternateTape,

Going a little overboard there in my opinion. If one of the major distributions would catch something sketchy, a whole bunch of tech savy would be all over it in no time.

dewritoninja,

This point just compile from source

moreeni,

Somebody could’ve pushed malware in the code, write all software yourself.

hunter2,

Someone could’ve pushed a malicious compiler. Better write all the bits by hand.

OddFed,
@OddFed@feddit.de avatar

Someone could have compromised the CPU interface, better build one from scratch.

russjr08,
@russjr08@outpost.zeuslink.net avatar

Someone could’ve compromised the materials used to build the CPU, better assemble the atoms together one by one.

Sidewayshighways,

Someone could’ve hidden something malicious in all that empty space between the atoms, better come up with a whole new structure of the universe

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • [email protected]
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • oklahoma
  • Socialism
  • KbinCafe
  • TheResearchGuardian
  • SuperSentai
  • feritale
  • KamenRider
  • All magazines