freedomofpress / securedrop-workstation-docs

User documentation for the SecureDrop Workstation
https://workstation.securedrop.org/
GNU Affero General Public License v3.0
5 stars 4 forks source link

Check ISO matches .DIGESTS #239

Closed deeplow closed 3 months ago

deeplow commented 3 months ago

Adds a step to confirm that the ISO matches the DIGESTS. Assuming the user didn't follow the Qubes OS verification link, under the previous scenario, a compromised ISO could still be malicious, even if the DIGESTS do match.

deeplow commented 3 months ago

I had missed this in my review of https://github.com/freedomofpress/securedrop-workstation-docs/pull/228. I think it is safe to assume that the previous instruction only pointed to the Qubes ISO verification instructions and the "latest" branch 404s.