Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another reason why you should be getting software via distro, with searate maintainers taking care of it there rather than directly from the developers that can inject malware via the very next version you mindlessly pull in without checking.

Also due to here being usually more than one distro, more people will look at the code & can spot the usptream getting rogue or getting compromised.



Adding MITM to your chain of trust doesn't make it more trustworthy, it adds an extra possible attacker.


Often there is vetting before one becomes a distro maintainer & even if one of them gets compromised, the blast radius is at least limitted to that one distro, rather than "everyone" like in case of NPM & co. Non rolling distros aslo have various policies for package updates, making it much harder to get a compromised package to all supported distro versions before it is eventually discovered.


Actually it does. The repo maintainer is on the user's side, so they are doing MITM on the attack vector. This makes it harder to get your malicious code in, because MITM might intercept it.

Yes now you have to trust the maintainer but that's sometimes easier.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: