|
|
|
|
|
by SwellJoe
4227 days ago
|
|
You're right, and I agree with you. Packages that are signed by a trusted party are a reasonable choice; anything less is not reasonable. But, lots of people add third party software repositories without out-of-channel confirmation of signing keys, and without any awareness of the risks involved in that. I see it more than most (I support server-side software products with a million or so installations), and I'm amazed at how often third party repos are enabled on people's systems, seemingly without any reason other than "more software is better". They often don't even know why/when they enabled those other repos or who operates them. That's no different than this curl+pipe scenario. |
|
Systems need to be safe by default and they should largely service the needs of users. Distros are no longer doing that.