• 0 Posts
  • 77 Comments
Joined 2 years ago
cake
Cake day: June 11th, 2023

help-circle




  • You should always verify signature and hash for any software you are installing but also keep in mind that if someone was really trying to send you a malicious download then there’s good chance that they will also deliver you a malicious signing key and hash. And there is really no good solution. If it is critical you can try to get signings keys from different places and with different IPs and maybe even different devices but pick and choose how long do you want to go down this rabbit hole.






  • Anna@lemmy.mltoLinux@lemmy.ml"SO proof" distro
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    24 days ago

    If you’re not going to give her sudo access then I’d say it’ll be really hard maybe even impossible to screw up. Also maybe setup a cron job that’ll do auto updates and if needed add in a check to make sure it isn’t uninstalling anything. Also how about immutable distro.



  • It is not about police hijacking IMEI, my bank only provides 2FA with phone number, and the password can be reset using the OTP they send to my phone. I know the bank is terrible but where I live all banks do same thing. So if my phone ever gets stolen they can just remove the sim and put it in another phone and get access to the Bank account. Also did I mention you can also get username from OTP to your phone so, yeah I should probably not use any bank and go live in mountains. But SIM lock helps.