3 ms·
Thanks for commenting this! I've seen this website before and it's really unfortunate how much attention it gets. APT's use of plain text HTTP (even with GPG)
by jdamato 8y ago
Thanks for commenting this! I've seen this website before and it's really unfortunate how much attention it gets.
APT's use of plain text HTTP (even with GPG) is vulnerable to several attacks outlined in this paper: https://isis.poly.edu/~jcappos/papers/cappos_mirror_ccs_08.pdf https://isis.poly.edu/~jcappos/papers/cappos_mirror_ccs_08.p....
Yes, this paper is old, but APT is still vulnerable to most of these attacks. I would advise anyone wanting to use APT to do so only with TLS.
- loeg 8y agoThe criticisms in that paper either do not apply to Apt as described in TFA or amount to DoS attacks. HTTPS does not and can not solve DoS.