4 ms·
This post is misleading I think, the problem as described in [1] is with the TLS server in gnutls, regardless of the client software. How does that impact packa
by resfirestar 6y ago
This post is misleading I think, the problem as described in [1] is with the TLS server in gnutls, regardless of the client software. How does that impact packages like apt and mutt, which aren’t serving anything?
To be fair, the post does mention this, but I’m struggling to see why the author would mention those packages in the first place except for sensationalism.
[1] https://gitlab.com/gnutls/gnutls/-/issues/1011 https://gitlab.com/gnutls/gnutls/-/issues/1011
- nine_k 6y agoNo idea about mutt, but it does affect apt repos if they are served via GnuTLS, though not the client apt software.
- resfirestar 6y agoIf the repos were served with GnuTLS (not likely), it wouldn’t matter if the apt client used GnuTLS or not.
- lmm 6y agoThey're talking about the debian package called "apt", not the binary called "apt", so it's possible that it includes a server?
- resfirestar 6y agoIt doesn’t.
- vesinisa 6y agoapt (dpkg) binaries need to be anyway PGP signed, so HTTPS is just a another layer of security, which is mostly redundnant. Not too long ago, apt in fact predominantly used HTTP. However, then this MITM vulnerability was found that would've been avoided by using HTTPS, and I think they pretty much switched to using HTTPS from then on: https://justi.cz/security/2019/01/22/apt-rce.html https://justi.cz/security/2019/01/22/apt-rce.html
- asveikau 6y agoI thought apt repos are just usual web servers. I don't think it's common to use gnutls for a web server.