|
|
|
|
|
by geofft
3740 days ago
|
|
Yes, making this change is bad for security, unless you have some other means of being informed of vulnerabilities. If you think pkg has vulnerabilities, fix them. (For instance, running as not-root is a great idea!) The author's argument that pkg is bad because Debian apt has vulnerabilities is ... really stretching. |
|
I assume their consideration is that the list might not be trustworthy, so knee jerk updating based on a potentially faulty list is itself a vulnerability. Would a 24h delayed updated list of security updates be worse than an incorrect one?