Re: Downloads page has insecure gpg-pubkey.asc and misnamed sha256 file

Originally Posted by
softmoth
The gpg-pubkey.asc PGP signing public key is served over HTTP. This is insecure and could enable a MITM attack.
I don't see this as a real problem. After downloading the "*.sha256" and "*.asc" file, I used GPG to verify the signature. The GPG system provides enough protection against MITM attacks. It arguably provides better protection than does the use of "https".
After you download that key, you should use GPG to attempt to verify some of the signatures on the key.
The SHA256 checksum file uses different file name than download, so sha256sum -c doesn't work.
Yes, I agree that this can be a problem.
I avoid it by going directly to https://download.opensuse.org/tumbleweed/iso/ for downloads, and I download the file that has the snapshot number as part of the file name. Hmm, I notice that this page is actually served by "https".
openSUSE Leap 15.4; KDE Plasma 5.24.4;
testing Tumbleweed.