|
|
|
|
|
by mpeg
3798 days ago
|
|
That can happen regardless of HTTP/HTTPS, say if the site was hacked they could be serving a bad key/signature, which is why you should always obtain the public GPG key (in any scenario, really) via a trusted channel, or multiple ones. So for instance in this case you could grab the gpg key, go into their IRC channel and ask for it again, etc. I do agree HTTP makes it easier to MITM, but in theory if you are serious about security you should not be relying on HTTPS alone. |
|
On those types of networks, MITM attacks are extremely easy, and there are tools to do it in seconds. It may be more likely for you to get MITM'd and have them modify the signature, than for the actual website to get hacked. Combined with the fact that some people would try to download Tails across these types of network for the added anonymity.