3 ms·
It's worth noting that deb packages are signed by the distro and any modification would be detected. That makes HTTPS unnecessary in this case.
by RealStickman_ 4y ago
It's worth noting that deb packages are signed by the distro and any modification would be detected. That makes HTTPS unnecessary in this case.
- Avamander 4y agoBut you have exposed the entire HTTP and GPG stack to the attacker. It would be unnecessary if those were as secure and under as much scrutiny as TLS libraries are.
- iso1631 4y agoThe argument would be that it's easier to see what someone is downloading (and thus infer installing) by sniffing the http traffic rather than https Sure you can do some form of fingerprinting with request sizes over https, but that's another step and no guarentee (which of two identical length files did they get for example) What the risk is to this information is another matter.
- sgtcodfish 4y agoHaving the communication in cleartext also makes it much easier for attackers to interfere with! Sure, they can't modify the .deb without failing signature verification, but they _can_ inject arbitrary delays in downloads or interfere with anything else which isn't signed (e.g. HTTP headers) Plus, if a vulnerability was discovered in the signing tool which enabled signature verification bypass with a certain signature format, HTTP makes it easy for attackers to perform that attack. TLS shouldn't be optional for installing packages today IMO - the extra guarantees it provides are worth it even with signature verification enabled.
- ducksinhats 4y agoAlso worth noting that there have been apt RCE's capable of being exploited by a MITM. https://www.debian.org/security/2016/dsa-3733 https://www.debian.org/security/2016/dsa-3733 https://justi.cz/security/2019/01/22/apt-rce.html https://justi.cz/security/2019/01/22/apt-rce.html I really don't see how anyone can still defend not using TLS for debian packages.