3 ms·
Why? Isn't that how most linux distros do their repos?
by someNameIG 1y ago
Why? Isn't that how most linux distros do their repos?
- charcircuit 1y agoIt is, but Linux distros are not the pinnacle of security. They use a security model decades out of date, so they are not something you should try and copy off of.
- someNameIG 1y agoBut has there been many actual reported security issues due to it? Like has anyone downloaded malware fro the official Ubuntu or Fedora repos?
- charcircuit 1y agoCVE-2008-0166 a maintainer added a security bug to openssl and it was distributed to many machines resulting in many weak ssh keys being generated. Between openssl releasing their library and it making its way to end user's machines a security vulnerability was injected.
- AAAAaccountAAAA 1y agoThat was literally before the first production Android phone become available. Does not seem to be a particularly common occurance. Though due to the current world situation, supply chain attacks might admittedly become more common.
- array_key_first 1y agoSure, but the reality is that your average Linux distro repo has WAY less malware than the play store. Your security model doesn't matter much when the people doing the security are bad actors. Google is a malicious actor - they actively incentivize malware on the play store.