[Bug 1534967] Re: ubuntu distro hashes insecure against MITM attacks (when not using GPG)

2016-01-19 Thread Seth Arnold
Since we publish a few thousand images it doesn't make sense to put the hashes themselves in the wikipages. What we need is the various GPG keys that we use published somewhere. I've asked the website team to make this list available but it's obviously a very low priority for the team. In the

[Bug 1534967] Re: ubuntu distro hashes insecure against MITM attacks (when not using GPG)

2016-01-16 Thread Thomas Mayer
There's some documentation about how to check the hash with gpg and which key is authorized at https://help.ubuntu.com/community/VerifyIsoHowto . This page is linked in https://help.ubuntu.com/community/UbuntuHashes . So finally, there is a statement available which key should be valid. Plus, this