3 ms·
Sibling comments have discussed how this affects Debian, Ubuntu, and opensuse -- any Arch users know how this affects us? Seems like official repos should be fi
by snackematician 7y ago
Sibling comments have discussed how this affects Debian, Ubuntu, and opensuse -- any Arch users know how this affects us? Seems like official repos should be fine but what about packages from the AUR?
- snazz 7y agoI don’t think the AUR has a concept of package signing—a PKGBULD will often download a tarball from somewhere and any signing is ad-hoc. The official repositories use their own key ring (which is distributed without a key server).
- majewsky 7y agoCorrect. The only time when this would concern you is when you add a third-party repository, e.g. one of [1]. This usually involves a manual TOFU step where you do the equivalent of `gpg --recv-keys $ID` on the pacman keyring. [1] https://wiki.archlinux.org/index.php/Unofficial_user_repositories https://wiki.archlinux.org/index.php/Unofficial_user_reposit...
- jwilk 7y agoBeware that "gpg --recv-keys <keyid>" (or even "gpg --recv-keys <fingerprint>"!) can be tricked into inserting malicious keys into the keyring: https://dev.gnupg.org/T3398 https://dev.gnupg.org/T3398
- deleted 7y ago[deleted]
- mikedilger 7y agoMy /etc/pacman.d/gnupg/gpg.conf had this line: keyserver hkp://pool.sks-keyservers.net