this post was submitted on 18 May 2025
243 points (97.3% liked)

Buy European

5873 readers
467 users here now

Overview:

The community to discuss buying European goods and services.


Matrix Chat


Rules:

  • Be kind to each other, and argue in good faith. No direct insults nor disrespectful and condescending comments.

  • Do not use this community to promote Nationalism/Euronationalism. This community is for discussing European products/services and news related to that. For other topics the following might be of interest:

  • Include a disclaimer at the bottom of the post if you're affiliated with the recommendation.

  • No russian suggestions.

Feddit.uk's instance rules apply:

  • No racism, sexism, homophobia, transphobia or xenophobia
  • No incitement of violence or promotion of violent ideologies
  • No harassment, dogpiling or doxxing of other users
  • Do not share intentionally false or misleading information
  • Do not spam or abuse network features.
  • Alt accounts are permitted, but all accounts must list each other in their bios.
  • No generative AI content

Benefits of Buying Local:

local investment, job creation, innovation, increased competition, more redundancy.

European Instances

Lemmy:

Matrix:


Related Communities:

Buy Local:

Continents:

European:

Buying and Selling:

Boycott:

Countries:

Companies:

Stop Publisher Kill Switch in Games Practice:


Banner credits: BYTEAlliance


founded 3 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] Angry_Autist@lemmy.world 1 points 1 day ago (1 children)

How are they 'changing on the fly' the distro I downloaded the week before and ran a CRC check on?

Any tools you use could similarly be compromised to give you untrustworthy output.

Serious question, do you have any background in IT security?

I ask that because to cover this properly will take effort, and I'm not prepared to waste that on someone who won't understand what I'm writing.

[โ€“] AwesomeLowlander@sh.itjust.works 1 points 1 day ago (2 children)

How are they 'changing on the fly' the distro I downloaded the week before and ran a CRC check on?

Well, you're uploading it remotely at some point. Essentially it's a supply chain attack, where during the process of upload it's compromised by the remote server. The logic would be - they can fingerprint any reasonable distro you might use, and replace it with a pre-prepared compromised version. Any tools you might use to check its veracity could potentially be poisoned the same way, no? As I said, remote possibility and high cost, but not implausible.

Serious question, do you have any background in IT security?

A little. I'm in IT, and know the basics.

[โ€“] Angry_Autist@lemmy.world 1 points 1 day ago

and as for 'tools I might use to check', literally anyone can code their own CRC checker in python with no python experience in like 20 mins using widely attested public algorithms

[โ€“] Angry_Autist@lemmy.world 1 points 1 day ago

A little. Iโ€™m in IT, and know the basics.

Then you understand how statistically impossible it is to craft a modified distro that passes a CRC check?

And by statistically impossible, I mean this in a thermodynamic sense, as in that it is much more likely that you are a brain floating in a void that cohered completely from nothingness due to vacuum energy than it is that any given iteration of a modified file of considerable length will match the same CRC as an established, published, vetted copy.

It is about 100 times easier to randomly guess the private key of a bitcoin wallet than it is to iterate arbitrary changes to match CRC results.

There is a reason it is still the gold standard of file authenticity despite it being literally based on a largely unchanged 50 year old technology.