4 ms·
> wget -O - "http://gpl.savoirfairelinux.net/ring-download/ring.pub.key" http://gpl.savoirfairelinux.net/ring-download/ring.pub.key" | sudo apt-key add - Ew.
by RaleyField 11y ago
> wget -O - "http://gpl.savoirfairelinux.net/ring-download/ring.pub.key" http://gpl.savoirfairelinux.net/ring-download/ring.pub.key" | sudo apt-key add -
Ew.
- anonbanker 11y agoLinux is scary, huh?
- RaleyField 11y agoTo spell it out for you, sending keys unauthenticated is scary. Double scary because these folks are writing security software so it ought to be in their motor memory to avoid trivial mitm attacks.
- Elv13 11y agoThanks for noticing, this is indeed quite bad, I opened a ticket to have this fixed
- anonbanker 11y agoso, check the key against a public registry. doesn't apt-key already do that when adding the key?
- RaleyField 11y ago> so, check the key against a public registry The problem with public registries is that anyone can spam them. Checking the key would involve retrieving it via multiple sources which is tedious. > doesn't apt-key already do that when adding the key? Man page doesn't say, nor can I find quickly on Google if apt-key does any additional verification. It doesn't seem likely though, because if verification step did occur the entire command would be redundant as the same mechanism that verified the key could be used to verify source list entry.