Hacker News new | ask | show | jobs
by Aldo_MX 3705 days ago
This has been thoroughly discussed when the website was compromised.

https://lwn.net/Articles/676664/

https://news.ycombinator.com/item?id=11149839

https://news.ycombinator.com/item?id=11142986

1 comments

Yeah, I know about that. Certainly, not a proud moment in Mint's history, but it got resolved quickly. But I'm not going to rule out Mint just because they got hacked once. kernel.org got hacked, after all.
They basically had no effort in their security, no idea how long they were compromised, and couldnt even respond effectively. I was a big fan of Mint usability who reluctantly had to ditch it.
None of these statements are correct.
These are the statements of the security people here that were going tgrough the data. The level of severity and recovery time supported thrur claims a bit.
> They basically had no effort in their security,

This is clearly hyperbole. "no effort"? C'mon.

> no idea how long they were compromised, and couldnt even respond effectively.

The hacked .iso was up for less than 24 hrs, so that puts a hard limit on the worst part of the compromise. The forum issues they fixed in a couple of days. This seems like a reasonably effective response to me.

> I was a big fan of Mint usability who reluctantly had to ditch it.

Did you really have to ditch it? Or did you just decide to go with a distro that emphasizes security over convenience? (Which is, of course, a completely reasonable thing to do, but others may make other (also reasonable) choices.)

I recall my initial data on the situation was in link and comments here:

https://news.ycombinator.com/item?id=11142986

The hacker who's comment is number one should tell you what level of security they have going on.

You are failing to read the "thoroughly discussion", the hack was just the tip of the iceberg.

Also, kernel.org was hacked because a rootkit gained access to their servers, not because they used a weak password like `upMint`, so you shouldn't compare both incidents.

No, I read all of the "thorough" discussion. I found it unconvincing.