Skip to content

Comment on Amazon Cloud Traffic Is Suffocating Fedora's Mirrorsparent

Comments

A digital signature does not protect you against a malicious actor who starts distributing outdated, vulnerable versions to you.

How do i know you don't know what your talking about?....a mystery ;)

I mean replay attack and freeze attack as described in https://doi.org/10.1145/1455770.1455841 . It's very likely that I'm not up to date on mitigations in individual package managers.

all of these package managers have vulnerabilities that can be exploited by a man-in-the-middle or a malicious mirror.

Well, that's how software is, but that article is from 2008 and things have gotten a lot better in the meantime (I think archlinux wasn't even signing their packages back then).

If the distribution's private keyring isn't compromised and you don't have third-party repos, your packages are as trustworthy as your distribution team (and upstream).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.