4 ms·
Luckily it only affected fetching the source and not the pre built binaries. Otherwise this would be a total nightmare.
by TimWolla 12y ago
Luckily it only affected fetching the source and not the pre built binaries. Otherwise this would be a total nightmare.
- hadoukenio 12y agoNo, the nightmare is still there. Most Debian mirrors only serve HTTP and you most likely installed Debian from an ISO that you downloaded over HTTP. And when you did an md5 of the downloaded ISO you probably compared it to a fingerprint hosted on a website served via HTTP (at the same time forgetting that md5sum could have been compromised itself since you downloaded it via HTTP). Then when using APT to install packages, they too are being installed via HTTP.
- TimWolla 12y agoapt checks the package signatures using GPG.
- hadoukenio 12y agoIt checks and verifies using the tools you downloaded via HTTP which could have been compromised via MITM?
- vWil 12y agoSee https://wiki.debian.org/SecureApt https://wiki.debian.org/SecureApt and https://www.debian.org/CD/verify https://www.debian.org/CD/verify