Xubuntu's site serving a crypto clipper is a critical reminder: A SHA256 hash is useless when the server is compromised.
Attackers change the hash, too. You MUST verify the GPG signature.
Here's how to do it right:
#DontTrustVerify #OpSec #GPG #Xubuntu

A Blog by Expatriotic
Verifying Software Tips
Thorough guide to verifying your software downloads, using Ubuntu LTS as our main example.



