4 ms·
Yes, they are signed, but not with the official key. If you add it through the UI, it will auto-accept the key from the repository. (I'm not sure how it exactly
by acatton 3y ago
Yes, they are signed, but not with the official key. If you add it through the UI, it will auto-accept the key from the repository. (I'm not sure how it exactly works, it might ask the user for the confirmation)
If you do it from the command line, by editing files, you will have to add the key manually.
But most inexperienced users will just copy/paste and run the "curl | sudo apt-key add" command from the shady repository website, because they want to run the software.
This is not much different from downloading an .exe from an untrusted website, and ignoring the warning from windows when running the .exe.
- TechBro8615 3y agoUntil recently (when apt-key was deprecated), this has been a large security hole (and it will continue to be as long as apt-key is still used). Basically unless a repository in your sources.list includes a signed-by attribute referencing a specific key, then it can install packages signed by any public key you've added via apt-key. Also, sources.list defines an implicit priority order (IIRC it's top-to-bottom), so that when two repositories include a package with the same name, the package from the highest priority repository is installed. You can imagine the security issues that arise from a system dependent on the order of lines in a file that many people manually edit while frustrated and reading a tutorial online. More here: https://medium.com/@glegoux/ubuntu-22-04-jammy-jellyfish-apt-key-is-deprecated-2dbbee8aec84 https://medium.com/@glegoux/ubuntu-22-04-jammy-jellyfish-apt...
- mistrial9 3y ago"people who walk on the sidewalk often cross the street in front of traffic THEREFORE walking on the street is just like walking in front of traffic" maybe you intend to deeply explore the behavior of "the most inexperienced" as if it is Typical of Desktop Linux admins?