4 ms·
Unfortunately, even the maintainers of dpkg/apt, who rely on GPG extensively, don't manage to plug all holes: https://blog.packagecloud.io/eng/2018/02/21/attack
by moosingin3space 8y ago
Unfortunately, even the maintainers of dpkg/apt, who rely on GPG extensively, don't manage to plug all holes: https://blog.packagecloud.io/eng/2018/02/21/attacks-against-secure-apt-repositories/ https://blog.packagecloud.io/eng/2018/02/21/attacks-against-...
Personally, I'm of the opinion that APIs should be as misuse-resistant as possible, and GPG is notoriously intransigent about actually acting as a well-designed API. Additionally, The Update Framework (TUF, https://theupdateframework.github.io/ https://theupdateframework.github.io/) prevents these issues by design.
- asveikau 8y agoThanks for that. I know that Debian has had security blunders in the past (RNG problems anyone?) so as I typed it I had some hunches, but... Importantly though, it's a big project which in this specific instance meant that someone on earth did end up scrutinizing and publishing exactly the sort of thing you linked.