4 ms·
Hash verification is extremely important to protect against supply chain attacks on apt. Also, apt itself is supposed to be protected by distro’s key, but did
by DethNinja 3y ago
Hash verification is extremely important to protect against supply chain attacks on apt.
Also, apt itself is supposed to be protected by distro’s key, but did any distro ever wrote how master keys are securely stored? Is there any other reasonable way to know that apt and entire Linux supply chain hasn’t been compromised already?
- madwebness 3y agoI would very much like to hear an answer to that from somebody who understands the subject deeply. Honestly, these days, I use containers for almost anything unusual and I don't update much either - precisely because anything you install with `apt` would have access to ALL of your system or at least limited access in read-only mode for some files and directories. And I would like to know if anyone can answer the same question for FreeBSD.
- bombolo 3y agodocker by default gives root access.