Settings

Theme

HTTP redirect vulnerability in apt package manager

lists.debian.org

10 points by dansimau 7 years ago · 5 comments

Reader

mondoshawan 7 years ago

Ironic, given the previous discussion on why apt shouldn't use HTTPS connections. With full end-to-end SSL validation, this kind of vulnerability can't exist. Should be interesting to see how the community reacta to this.

est31 7 years ago

Weren't PGP signatures supposed to ensure integrity? How is this being bypassed?

jwilk 7 years ago

Please use the original title.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection