Hacker News new | ask | show | jobs
by severino 1955 days ago
> How is this is an issue? It doesn't require any login and this is exactly what happens with every APT mirror.

Yes, but it's you who usually manage those mirrors, not some guy deciding which mirrors your apt must query now and pushing it in a regular update without notice.

I don't care if it's Microsoft or some obscure Chinese repo, but I think nobody should mess with your mirrors list or trust their keys in this way.

2 comments

If you don't want "some guy" deciding which APT mirrors you use, then don't use "some guy's" linux distribution
No, it doesn't work like that. You pay for something and you complain. Even if you don't. And if the guy doesn't like criticism, he can quit at any time.
> Yes, but it's you who usually manage those mirrors,

That's not true for most people.