|
|
|
|
|
by msbarnett
3738 days ago
|
|
The fact that pkg isn't least-privileged in its operations sucks, but the idea that this somehow makes the contents of a cryptographically signed vulnerability list, fetched via SSL with chain-of-trust verification "untrustworthy" is nonsensical. |
|
You're protected from MITM and hacked repos, but what if the problem is in the official repo?
Defensive programming is useful.