4 ms·
Yeah... only idiots "sudo aptitude install" without reading and building from source first!
by mcantor 14y ago
Yeah... only idiots "sudo aptitude install" without reading and building from source first!
- dsl 14y agoYou really can't tell the difference between blindly executing input from an insecure HTTP connection, and installing packages with a tool that verifies cryptographic signatures against known good keys shipped with your distro? Mr. Cantor, I have added to the list of people to never hire I keep in my notebook.
- huhtenberg 14y agoThe risk of picking up malicious executable from the legit server is far higher than that of picking up a malicious executable from an impersonating server. Practically speaking.
- soc88 14y agoSo what? The package manager will not install it. So it is still thousand times better than downloading random things from the net.
- mcantor 14y agoSo? Who says the verified package isn't malicious? My point isn't about cryptography, it's about complexity. Unless you personally read through every line of code, how do you really know that there isn't something in there waiting to screw you over?
- aw3c2 14y agoI trust my system's package maintainers and the signing makes sure that it is them. I do not trust a random website that could easily be MITMd.
- VMG 14y agoSo you'd be fine with https?
- brohee 14y agoYou don't know. What you know however is who to sue if the package ends up being malicious, thanks to the signature.
- batista 14y agoAnd I've added you to the list of guys that think they are "the shit" because they have hiring abillities (in some shitty company) and need to tell it on the intertubes.
- walrus 14y agoYou can explain the difference without attacking the person you're replying to.