Bonum Certa Men Certa

Microsoft Edge for “Linux” Uses Outdated GPG and Then Configures it to Silence Your Distribution’s Package Security Checks

Reprinted with permission from Ryan

Previously: Bruce Schneier: Microsoft Edge is Apparently a Password Stealer Too, Even on GNU/Linux

Microsoft Edge for “Linux” uses outdated GPG and then configures it to silence your distribution’s package security checks.



I got bored today and decided to look at the RPM package for Microsoft Edge for “Linux”.



If you installed it, it will add a microsoft-edge.repo file in etc/yum.repos.d with the following:



[microsoft-edge]
name=microsoft-edge
baseurl=https://packages.microsoft.com/yumrepos/edge/
enabled=1
gpgcheck=1
gpgkey=https://packages.microsoft.com/keys/microsoft.asc


As you can see, Microsoft has essentially bypassed the GPG check by enabling the check, and then instead of installing a package signing key into the RPM database, like well behaved software does, they point it at a Public Key hosted on their server.



The gist of this is that it shuts up the “package is unsigned” warning that prevents tampering, but then provides no assurances that Microsoft Edge updates are actually not tampered with.



If an attacker compromises Microsoft’s server, they could replace the key, then replace Microsoft Edge with a package containing anything (or just add malware to Edge to increase the amount of time before people realized anything was wrong with the package), and it would pass the signature check because DNF would check the URL and find the attacker-modified microsoft.asc Public Key.



Additionally, by following the URL to the Microsoft Public Key block, I noticed that they are using an outdated branch of GPG as well, which dates back to 2004 and is only maintained to address CVEs.



GPG recommends migrating to the current branch (2.3.8 is the latest as of this writing), and Mullvad VPN warns its users not to use the 1.4 branch as well.



Additionally, GPG says that the 1.4 branch is not widely used, so there’s likely fewer people legitimately studying it to fix it, and more likely just attackers looking for slobs that are still using it, like Microsoft.



This should be yet another example of how much Microsoft can be trusted to “secure” your computer.



They can’t even secure their own. They had a couple of major data breaches thanks to misconfiguration of Azure recently, which even BleepingComputer covered.



I hope that if you’re considering putting Microsoft software where it doesn’t belong, on your GNU/Linux system, then witnessing their slovenly practices should give you some second thoughts.



Just this repo alone sets up your GNU/Linux system to be seriously compromised.



The point of installing GPG keys into RPM is so that when there’s a breach of the server, it doesn’t affect users that already have the program and get alerted that there’s an update. A legitimate update which updates RPM with the new GPG key would have to be signed using the old one, meaning that a chain of trust is preserved.



When you point it at a Web site, like Microsoft does, you have no idea what you’ll get.



Recent Techrights' Posts

SLAPP Censorship - Part 30 Out of 200: The Time We Reported Abuse to Greater Manchester Police (GMP) and It Was Escalated to Its Cybercrime Unit
he started trolling and harassing me for criticising his employers' monopolistic and users-hostile agenda
Hardly Seeing Slopfarms Today, Even in Google News
Google's adventures with slop increased its debt significantly
 
Links 02/04/2026: Apple Turns 50, Efforts To Ban VPNs
Links for the day
Gemini Links 02/04/2026: Kubernetes With FreeBSD, OFFLFIRSOCH, and Great Circle Distance
Links for the day
Dr. Andy Farnell on Microsoft Silencing or Deplatforming Opposition in the UK and Elsewhere
Microsoft as a king or a kind of "religion" one cannot question
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 01, 2026
IRC logs for Wednesday, April 01, 2026
'Modern' Cars Not a Rosy Industry
The current "modern" cars already have a shelf life similar to that of many toothpastes
Wrongthink Detector and Filter in "Think About the Children" Clothing
It is not about "age verification", it's a Trojan horse for social control
IBM Facilities Now Deemed Legitimate (Military) Target, Along With GAFAM Bases
Does IBM have any defences in place to protect against "downtime by explosions"?
What Happens When Some Large News Sites Turn to Slop and Spew Out Nonsense
LLM slop makes such grotesque mistakes abundant
Links 01/04/2026: Quantum Hype (Turing and Google), "US Fuel Prices Surge Past $4 a Gallon"
Links for the day
Gemini Links 01/04/2026: "Sacred Week of Cycling" and Zenity for Scripts
Links for the day
Losing Debian: Sruthi Chandran election flop
Reprinted with permission from Daniel Pocock
French judgment: parasitisme by FSFE & Matthias Kirschner (CO23.002709)
Reprinted with permission from Daniel Pocock
Microsoft Uses April Fools to 'Joke' About Inserting "Age Verification" (Surveillance) Into Linux
MinceR says the "lkml [message/page] one is April Fools or at least they're trying to pass it off as April Fools [however] the [GitHub] one was archived on the 8th and yesterday, so that probably isn't..."
IBM "Headcount Reductions" by Early Retirement and Death
The tragedy at IBM started 33 years ago on the first of April
Red Hat: Latin-1 character set under threat from Bishop Michael Martin, North Carolina
Reprinted with permission from Daniel Pocock
Links 01/04/2026: Microsoft GitHub Now Pushing Ads Into People's Code/Commits, Earth Overshoot Day Draws Nearer
Links for the day
What IBM and EPO Workers Have in Common: European Media Not Covering Very Major News (Press Became Dysfunctional)
Are IBM operatives working to scuttle the process of investigative journalism?
Free Speech in the United Kingdom When "Chilling Effect" is Increasingly Prevalent
If politicians cannot even use a term like "parasitic behaviour", then where do we as a society end up?
Oracle Lays Off Because of Debt and Commercial Issues, Not Slop
Like Scam Altman, Larry Ellison hangs around Cheeto King because he could use some bailouts in the form of government contracts or phony money with an incredible name like "Stargate"
The Real Reason Many Sites and Forums Shun Microsoft Lunduke
When forums say that they banned Microsoft Lunduke or don't want him mentioned it's probably because they are familiar with the "stench" that follows him around
Gemini Links 01/04/2026: Hallucinations, Stitching, and Type Systems
Links for the day
Lots of Layoffs at IBM, "Media Blackout" About Mass Layoffs at IBM's HashiCorp and Confluent Last Month
IBM is a dying company circling down the drain while manipulating or paying the media to pretend everything is fine
Microsoft Under Investigation by the UK's Competition and Markets Authority (CMA) for Abusive Tactics
What's noteworthy is that this is "set to begin in May"
Sounds Like Red Hat (IBM) Layoffs in Slop Clothing
This is an IBM policy. They try to justify staff cuts.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, March 31, 2026
IRC logs for Tuesday, March 31, 2026
In Time for April Fools (and Easter), 30,000 Oracle 'Pink Slips' While People Are Asleep
Oracle probably has no choice but to fire a ton of people
SLAPP Censorship - Part 29 Out of 200: Violent Language Won't Go Away When You Use It in Your Site, Blog, and Social Control Media
abuse began in 2012 because I had politely and accurately criticised Red Hat
Gemini Links 31/03/2026: Five Years on Gemini (Rob's Gemini Capsule), OFFLIFIRSOCH 2026, and More
Links for the day
Slopfarms Persist, But Google Seems to Have Delisted Many
We are still checking
Links 31/03/2026: More Energy Shortages Noted, Taylor Swift Faces Trademark Infringement Suit
Links for the day
Chaff, Slop and Spam Help Distract From Parallel Crises at IBM
IBM seems very eager to undermine discussion about what goes on inside
Lacking Business Model, Bluesky Has Become Slop and Gravitates Towards Plagiarism, Bots
LLM slop/plagiarism under the guise of "Artificial Intelligence" (AI)
IBM-Spawned Lexmark Sold, Then Came Mass Layoffs, Now the CEO Who Did This is Leaving
IBM is really not a magnet for talent at this point
Not April Fools But April First: Red Hat Staff Becoming "IBM"
claims of mass layoffs set to kick off at IBM some time soon
Gemini Links 31/03/2026: Antenna Packed Up, AuraGem and AuraSearch Maintenance
Links for the day
Links 31/03/2026: More Social Control Media Bans, BBC Now Run by GAFAM (US) Executive
Links for the day
'Broligarchs' Don't Want Science, They Want Entertainers to Entertain Them (and Make Them Richer)
Of course this will result in things getting worse in the sciences and everyone who relies on the sciences
When Republics Turn From Democratic Governments Into Imperialistic Dictatorships
What goes on in the US would require talking about politics
Companies That Have Nothing Except Buzzwords and Promises Will Perish
Dishonest media will perish along with the companies it is covering up for
The Solicitors Regulation Authority (SRA) to be Grilled in Two Weeks' Time by the British Government for "Recent Regulatory Failures"
we escalated to our politicians
GNU/Linux Will Thrive as Long as It's Modular, Not Monolithic
To IBM, it's all about money. Nothing else matters.
EPO "Cocaine Communication Manager" - Part X - People Are Leaving
"I was happy to be at the EPO in the beginning, but since I realized it's all a big mafia"
IBM's 33 Years as a "Financial Engineering" (Accounting Tricks) Company
In relation to Red Hat, this "financial engineering" involves culling many workers and trying to replace them with slop
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 30, 2026
IRC logs for Monday, March 30, 2026
Links 31/03/2026: Rising Costs, Cyberattacks, Novo Patent Expiry
Links for the day
Gemini Links 31/03/2026: American Spring, Distributed Systems Simulator, and Calculus for Electronics
Links for the day