Hacker News new | ask | show | jobs
by Ajedi32 2705 days ago
APT already supports HTTPS. Enforcing it by default wouldn't increase APT's attack surface significantly.
1 comments

It would decrease the number/quantity/capacity of available mirrors. I don't know if that quantity would be significant.
You would lose the ability to do transparent caching which I agree is rather annoying, but I think most environments where that sort of caching occurs (mostly corporate and school networks) also have the means to explicitly configure client machines to use an internal caching mirror.
Those environments tend to MITM https traffic as well. At least the companies I've worked for can.
Those companies really need to learn what privacy means.
You could run a caching mirror for such things, such as artifactory for example.