3 ms·
As I mentioned there is no dnssec or tls on their archive site, with the package signature not being checked interested parties need to run a mirror of the real
by outsomnia 6y ago
As I mentioned there is no dnssec or tls on their archive site, with the package signature not being checked interested parties need to run a mirror of the real site with selected packages tampered and poison the dns of their target.
And then they can wait for the targets to update. They can do that pretty cheaply and over the 3 years and two major releases the broken opkg shipped on, just collect victims. That's what a lot of people in a lot of different countries are paid to do for a living.