4 ms·
I guess public linux distribution repo mirrors can still be http, if you are fine with leaking which packages you are installing. The packages themselves are s
by chme 5y ago
I guess public linux distribution repo mirrors can still be http, if you are fine with leaking which packages you are installing.
The packages themselves are signed and checked locally before installing them, so MITM shouldn't be possible. If your local trust is broken, then you lost already.
And you can easily setup caching proxies for the repos, without requiring to setup your own CA.
- beardog 5y agoWhile its not common enough to matter much, there have been cases of apt vulns (DSA-4371-1) which would give anyone who can exploit it with a MITM root access. One example of where this could lead to a wide spread attack is distros like whonix.org which update over Tor. They mitigate this with https/.onion package servers. Theres also the smaller problem of package-set fingerprinting like you said.
- Anunayj 5y agoThough https still has the privacy advantage, if I update over http, my ISP knows I downloaded the tor package, this information won't be leaked over https. and since it's minimal trouble to set up https, I think it's fine
- Xylakant 5y agoNote that deb packages are not usually signed unless something major changed in the last 5 years or so. The repository metadata is signed and contains a checksum of all packages. It’s all safe as long as you install from a repo, but installing a deb package directly doesn’t usually do signature checks. See https://www.debian.org/doc/manuals/securing-debian-manual/deb-pack-sign.en.html https://www.debian.org/doc/manuals/securing-debian-manual/de... AFAIR there are options to sign packages themselves, but there’s at least two competing incompatible signing schemes. rpm packages carry a signature in the package itself.
- solarkraft 5y ago> if you are fine with leaking which packages you are installing I'd rather not ...