|
|
|
|
|
by Chris2048
11 days ago
|
|
Looking at the Debian example: https://in-toto.io/docs/examples/debian/ Does Debian already provide signature on .deb files (that is, provide a manifest of their hashes and and sign each)? If so, you could potentially d/l the files from any source/mirror? |
|
Signing files is 90's security.
Yes, of course in 2026 it is still perfectly capable of proving a file has not been tampered with.
The problem is that is insufficient in 2026.
See the "Goals to protect against specific attacks" section[1] of TUF (The Update Framework) spec to give you an idea of modern attack vectors.
[1] https://theupdateframework.github.io/specification/v1.0.33/#...