Settings

Theme

HTTP redirect vulnerability in apt package manager

lists.debian.org

10 points by dansimau · 5 comments

Reader

3 threads
mondoshawan

Ironic, given the previous discussion on why apt shouldn't use HTTPS connections. With full end-to-end SSL validation, this kind of vulnerability can't exist. Should be interesting to see how the community reacta to this.

est31

Weren't PGP signatures supposed to ensure integrity? How is this being bypassed?

jwilk

Please use the original title.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection