|
|
|
|
|
by asdfasdf1231
2373 days ago
|
|
I never understood why domains used to NTP and Package mirrors depend on external, commercial, certificate authorities. It could be a fallback, with a red big warning to manually check the certs are alright when you need it (e.g too long without synching your root certificates package). But for most cases there is no excuse not having it local at all times. I mean MITM a domain essential for the "distro" should be at least just a little bit harder than regular MITM. |
|
Don't get me started on authoritative DNS security.