2 ms·
> a malicious mirror could still exploit a bug like this, even with https. But I suspect that a network adversary serving an exploit is far more likely than deb
by aboutruby 8y ago
> a malicious mirror could still exploit a bug like this, even with https. But I suspect that a network adversary serving an exploit is far more likely than deb.debian.org serving one or their TLS certificate getting compromised
Exactly, this is far more easily exploitable because apt is using HTTP by default instead of HTTPS