It makes it so that your mirror would have to be exploiting apt, instead of effectively anyone. As a result, using TLS for downloads would mitigate this (but not fix it).
I've read the arguments against HTTPS for apt many times. They're wrong.
I've read the arguments against HTTPS for apt many times. They're wrong.
No comments yet.