3 ms·
While its not common enough to matter much, there have been cases of apt vulns (DSA-4371-1) which would give anyone who can exploit it with a MITM root access.
by beardog 5y ago
While its not common enough to matter much, there have been cases of apt vulns (DSA-4371-1) which would give anyone who can exploit it with a MITM root access.
One example of where this could lead to a wide spread attack is distros like whonix.org which update over Tor. They mitigate this with https/.onion package servers.
Theres also the smaller problem of package-set fingerprinting like you said.