Hacker News new | ask | show | jobs
by LoSboccacc 2703 days ago
also, the apt way to fix this would be to a) move release.gpg out of the package path and b) require the release.gpg to be wrapped and signed with the previous valid key instead of being accepted blindly