public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* Identical Cygwin websites - differing downloads
@ 2023-06-15 13:20 happynumnums
  2023-06-15 15:07 ` marco atzeri
  0 siblings, 1 reply; 3+ messages in thread
From: happynumnums @ 2023-06-15 13:20 UTC (permalink / raw)
  To: cygwin

[-- Attachment #1: Type: text/plain, Size: 870 bytes --]

When looking for the latest Cygwin installer, I came across two different domains.

One insecure:
http://cygwin.org/

and one secure:
https://cygwin.net/

When checking the downloaded latest 3.4.6 installer with sha512sum.exe, I get differing checksums from the executables from both websites:

an unexpected checksum (from first site)
787c46173f5f91d350d31053f09d2bc18e1a80907a9f571f905fa7579cd2fa7b2502337da57aa70a5c8c4209a365f3604cee3c8ffe6c451b397986ddf17eea14

and the expected checksum from the 2nd site (as printed on both pages):
4779bead277ba7e682212ed3b1c9c2a56f9b15586dc2db3949556958b683b6f8a11c1c8957e1027d798281fcc98ccf12c418a609911c7e553787c88f8af86152

The first file size shows 1350kB, the 2nd 1356kb.

Can somebody clarify, if cygwin.org is a phishing site or otherwise explain the differences?

Sent with [Proton Mail](https://proton.me/) secure email.

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Identical Cygwin websites - differing downloads
  2023-06-15 13:20 Identical Cygwin websites - differing downloads happynumnums
@ 2023-06-15 15:07 ` marco atzeri
  2023-06-15 17:01   ` Brian Inglis
  0 siblings, 1 reply; 3+ messages in thread
From: marco atzeri @ 2023-06-15 15:07 UTC (permalink / raw)
  To: happynumnums; +Cc: cygwin

On Thu, Jun 15, 2023 at 3:20 PM happynumnums via Cygwin
<cygwin@cygwin.com> wrote:
>
> When looking for the latest Cygwin installer, I came across two different domains.
>
> One insecure:
> http://cygwin.org/
>
> and one secure:
> https://cygwin.net/
>
> When checking the downloaded latest 3.4.6 installer with sha512sum.exe, I get differing checksums from the executables from both websites:
>
> an unexpected checksum (from first site)
> 787c46173f5f91d350d31053f09d2bc18e1a80907a9f571f905fa7579cd2fa7b2502337da57aa70a5c8c4209a365f3604cee3c8ffe6c451b397986ddf17eea14
>
> and the expected checksum from the 2nd site (as printed on both pages):
> 4779bead277ba7e682212ed3b1c9c2a56f9b15586dc2db3949556958b683b6f8a11c1c8957e1027d798281fcc98ccf12c418a609911c7e553787c88f8af86152
>
> The first file size shows 1350kB, the 2nd 1356kb.
>
> Can somebody clarify, if cygwin.org is a phishing site or otherwise explain the differences?
>
> Sent with [Proton Mail](https://proton.me/) secure email.
>

all sites point to the same address and all works with HTTPS
IPv4 address (8.43.85.97)

https://sitereport.netcraft.com/?url=https://cygwin.net

problem/cache in the middle ?

Regards
Marco

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Identical Cygwin websites - differing downloads
  2023-06-15 15:07 ` marco atzeri
@ 2023-06-15 17:01   ` Brian Inglis
  0 siblings, 0 replies; 3+ messages in thread
From: Brian Inglis @ 2023-06-15 17:01 UTC (permalink / raw)
  To: cygwin; +Cc: happynumnums

On 2023-06-15 09:07, marco atzeri via Cygwin wrote:
> On Thu, Jun 15, 2023 at 3:20 PM happynumnums via Cygwin
> <cygwin@cygwin.com> wrote:
>>
>> When looking for the latest Cygwin installer, I came across two different domains.
>>
>> One insecure:
>> http://cygwin.org/
>>
>> and one secure:
>> https://cygwin.net/
>>
>> When checking the downloaded latest 3.4.6 installer with sha512sum.exe, I get differing checksums from the executables from both websites:
>>
>> an unexpected checksum (from first site)
>> 787c46173f5f91d350d31053f09d2bc18e1a80907a9f571f905fa7579cd2fa7b2502337da57aa70a5c8c4209a365f3604cee3c8ffe6c451b397986ddf17eea14
>>
>> and the expected checksum from the 2nd site (as printed on both pages):
>> 4779bead277ba7e682212ed3b1c9c2a56f9b15586dc2db3949556958b683b6f8a11c1c8957e1027d798281fcc98ccf12c418a609911c7e553787c88f8af86152
>>
>> The first file size shows 1350kB, the 2nd 1356kb.
>>
>> Can somebody clarify, if cygwin.org is a phishing site or otherwise explain the differences?
>>
>> Sent with [Proton Mail](https://proton.me/) secure email.
>>
> 
> all sites point to the same address and all works with HTTPS
> IPv4 address (8.43.85.97)
> 
> https://sitereport.netcraft.com/?url=https://cygwin.net
> 
> problem/cache in the middle ?

or Corporate/ISP proxy interfering?

As noted in the FAQ and the added footers, cygwin.com appears to be the 
preferred site, so should be used in preference to alternative aliases to avoid 
any possible issues.

-- 
Take care. Thanks, Brian Inglis              Calgary, Alberta, Canada

La perfection est atteinte                   Perfection is achieved
non pas lorsqu'il n'y a plus rien à ajouter  not when there is no more to add
mais lorsqu'il n'y a plus rien à retirer     but when there is no more to cut
                                 -- Antoine de Saint-Exupéry

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2023-06-15 17:01 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-06-15 13:20 Identical Cygwin websites - differing downloads happynumnums
2023-06-15 15:07 ` marco atzeri
2023-06-15 17:01   ` Brian Inglis

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).