▲ 334 ▼ What else should I help seed? (lemmy.world) submitted 2 years ago by InternetCitizen2@lemmy.world to c/linux@lemmy.ml 64 comments fedilink hide all child comments Just a small way to help people get their FOSS. What are some other projects that have torrents that would be good to seed?
[–] Maetani@jlai.lu 15 points 2 years ago (4 children) Verifiying the checksum of an iso takes 30 seconds... You don't need to trust anyone permalink fedilink source parent hideshow 8 child comments replies: [–] Sekki@lemmy.ml 9 points 2 years ago I don't think that is even necessary. If you download the .torrent file from a trusted source it will already contain a secure hash of the final file. Also every piece you receive also comes with a hash that can also be verified through the .torrent file. If you don't trust the source enough to provide a valid .torrent, I don't see how downloading the image directly from them makes any difference. Read more: Official BitTorrent BEP BitTorrent V2 and SHA-256 permalink fedilink source parent [–] weker01@sh.itjust.works 5 points 2 years ago Well you do need to trust the checksum provided. That is the one you are checking against. Better would be a signature from a key you trust. In the end a modern torrent is just a hash. permalink fedilink source parent [–] delirious_owl@discuss.online 2 points 2 years ago Checksum doesn't verify authenticity. You need to verify the signature permalink fedilink source parent [–] beeng@discuss.tchncs.de 1 point 2 years ago (1 child) Been on Linux 6 years, never done it. Extra steps permalink fedilink source parent hideshow 2 child comments replies: [–] CrypticCoffee@lemmy.ml 1 point 2 years ago (1 child) Length of time never means quality of decisions. Always best to validate. So easy to package up malware and farm folks bank accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] beeng@discuss.tchncs.de 1 point 2 years ago Hence my threat model hasn't included torrents. permalink fedilink source parent
[–] Sekki@lemmy.ml 9 points 2 years ago I don't think that is even necessary. If you download the .torrent file from a trusted source it will already contain a secure hash of the final file. Also every piece you receive also comes with a hash that can also be verified through the .torrent file. If you don't trust the source enough to provide a valid .torrent, I don't see how downloading the image directly from them makes any difference. Read more: Official BitTorrent BEP BitTorrent V2 and SHA-256 permalink fedilink source parent
[–] weker01@sh.itjust.works 5 points 2 years ago Well you do need to trust the checksum provided. That is the one you are checking against. Better would be a signature from a key you trust. In the end a modern torrent is just a hash. permalink fedilink source parent
[–] delirious_owl@discuss.online 2 points 2 years ago Checksum doesn't verify authenticity. You need to verify the signature permalink fedilink source parent
[–] beeng@discuss.tchncs.de 1 point 2 years ago (1 child) Been on Linux 6 years, never done it. Extra steps permalink fedilink source parent hideshow 2 child comments replies: [–] CrypticCoffee@lemmy.ml 1 point 2 years ago (1 child) Length of time never means quality of decisions. Always best to validate. So easy to package up malware and farm folks bank accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] beeng@discuss.tchncs.de 1 point 2 years ago Hence my threat model hasn't included torrents. permalink fedilink source parent
[–] CrypticCoffee@lemmy.ml 1 point 2 years ago (1 child) Length of time never means quality of decisions. Always best to validate. So easy to package up malware and farm folks bank accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] beeng@discuss.tchncs.de 1 point 2 years ago Hence my threat model hasn't included torrents. permalink fedilink source parent
[–] beeng@discuss.tchncs.de 1 point 2 years ago Hence my threat model hasn't included torrents. permalink fedilink source parent