Hacker News new | ask | show | jobs
by landgenoot 312 days ago
Package managers don't use https on purpose in order to make it easy to cache a repository.

This is alright from a privacy perspective, because you can find out which packages are downloaded anyway by looking at the download sizes.