> This is installed by adding a shady repository to your apt sources.list...
How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
How is this possible? Aren't the packages signed like on ArchLinux so that you can use any mirrorlist?
If you do it from the command line, by editing files, you will have to add the key manually.
But most inexperienced users will just copy/paste and run the "curl | sudo apt-key add" command from the shady repository website, because they want to run the software.
This is not much different from downloading an .exe from an untrusted website, and ignoring the warning from windows when running the .exe.
More here: https://medium.com/@glegoux/ubuntu-22-04-jammy-jellyfish-apt...
maybe you intend to deeply explore the behavior of "the most inexperienced" as if it is Typical of Desktop Linux admins?