Hacker News new | ask | show | jobs
by kiallmacinnes 2710 days ago
The signature method used by Linux mirrors has existed longer than HTTPS has, there's nothing homebrew about it.
1 comments

I trust the file signatures, but if you need to write a full article arguing something is secure then it can be made more secure by making the system simpler and more standard.
You are going to become very upset when you discover the simplicity of TLS.
The apt system is simpler. HTTPS is merely more popular, and breaks existing apt use-cases.