seems like a wide gaping hole in the process for checking integrity of e.g. linux distro releases

Many linux distributions recommend using downloaded signing keys to verify the integrity of downloaded checksums. This seems utterly ridiculous to me, since the downloaded keys are just as suspect as the downloaded checksums. And checking … Continue reading seems like a wide gaping hole in the process for checking integrity of e.g. linux distro releases