4 ms·
Private keys can be stolen or extracted via bribery, etc.
by pOVTVOItY 10y ago
Private keys can be stolen or extracted via bribery, etc.
- sigjuice 10y agoAre you saying if ubuntu served apt-gets over https, stolen private keys wouldn't be a problem?
- pOVTVOItY 10y agoMultiple layers of security is industry practice.
- sigjuice 10y agoSure. In this particular setting, having both https and pgp is definitely better and a third layer would be even better, though I cannot think of one. Successful transfer from https Ubuntu mirror says my package was not tampered with during transmission, but nothing about the validity and integrity of the package itself. The Ubuntu project most likely does not have absolute control over the various mirrors available to users, so pgp verification provides a further assurance that mere https cannot. If I had to chose between https and pgp, I would pick pgp. The OpenBSD project has a similar scheme (called signify).