4 ms·
> This presumes you use HTTP, have a compromised SSL cert, or have pissed off the NSA. This is not taking into content mirroring. TUF allows you to treat all m
by dmcgowan 11y ago
> This presumes you use HTTP, have a compromised SSL cert, or have pissed off the NSA.
This is not taking into content mirroring. TUF allows you to treat all mirrors as potentially malicious allowing anyone to reliably deliver trusted content, even in an untrusted network. GPG does not provide a way to detect active attacks other than signature verification.
- kordless 11y agoThis is still an apples to oranges argument. GPG is a way to sign data in a trusted manner, including data that is delivered by both trusted and untrusted systems. If you want to point fingers, point at APT, YUM or RPM, not GPG.