The process is to verify the Qubes ISO signature is correct, and not to 
trust a SHA256 checksum posted on the same website hosting the file. The 
hash only confirms the integrity and not the validity of the file (which 
may be infected). It's a security theater exercise we're used to doing 
elsewhere in order to provide us with the warm fuzzy feeling of a false 
sense of security.

Instructions here on how to verify the latest Qubes ISO is legitimate:
https://www.qubes-os.org/security/verifying-signatures/

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/7ba9c19f-a5be-40f8-96d1-15e0d067449c%40googlegroups.com.

Reply via email to