Get:13 http://security.ubuntu.com/ubuntu bionic-security/main The irony of using insecure http for your security subdomain...
-
-
Replying to @dascandy42
Packages are signed so, https wouldn't improve security
2 replies 0 retweets 0 likes -
Replying to @Cor3ntin
Actually it would. Imagine an exploit in apt or somebody giving you some exploitable daemon to install instead of your intended package
1 reply 0 retweets 1 like
Replying to @dascandy42 @Cor3ntin
The root of the archive is what is signed, so you can't replace individual packages. What you *could* do is roll back or pin the entire package archive to an older, vulnerable version.
12:20 AM - 20 Dec 2018
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.