-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Description
Description
Currently it is not documented how to verify the authenticity or cryptographic integrity of the downoads from parrotsec.org or parrot.sh.
This makes it hard for Parrto OS users to safely download Parrot ISOs, and it introduces them (and potentially their clients) to watering hole attacks.
Steps to Reproduce
- Go to the Parrot OS Documentation https://parrotsec.org/docs
- Navigate to Introduction -> Download Parrot https://parrotsec.org/docs/introduction/download-parrot
- Look for info on cryptographic verificaton
- ???
- Get confused and open ticket
Expected behavior: [What you expected to happen]
A few things are expected:
- I should be able to download the Parrot OS Release Signing PGP key out-of-band from popular third-party keyservers (eg https://keys.openpgp.org/)
- The documentation (https://parrotsec.org/docs/introduction/download-parrot) should include a page that describes [a] how to download the official Parrot OS Release Signing PGP Key, [b] how to download the
signed-hashes.txtfile, [c] how to usegpgto verify that the signature of thesigned-hashes.txtis authentic, and [d] how to usesha256sum --check(or similar tool) to verify that the integrity of the downloaded release file. - The downloads page itself (https://parrotsec.org/download/) should include a link to the documentation page above
Actual behavior: [What actually happened]
There's just literally no information on verifying downloads in the documentation.
Metadata
Metadata
Assignees
Labels
No labels