Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The packages you download can be easily inferred even transmitted over tls. What does tls buy you? That's the argument at least.

You could always download them over tor.



I think the concern is more about man-in-the-middle attacks. Even then, though, doesn't apt verify the hashes of downloaded packages?


How do you trust distribution if you also have mirrors all across the globe (that are not Cononical's machines)?


Signatures generated with trusted keys.


How does apt get said hashes? That's the key problem.


By checking a signature from a trusted key. MitM is handled.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: