Debian: "We don't need to use HTTPS, we sign our packages! Check out whydoesaptnotusehttps[.]com!"
https://lists.debian.org/debian-security-announce/2019/msg00010.html …
https://justi.cz/security/2019/01/22/apt-rce.html …
Oops.
*This* is why you use HTTPS. Defense in depth. Take note @videolan.
This is a reply to the behavior in the original ticket; I'm (now) aware at least some folks on the VLC side understand the merits of defense in depth. Now the *polite* thing would be to leave the ticket open (or dupe it to a master new-updater one); that would show commitment ;-)
-
-
Your statement is likely true (roadmap not public). However, "Take note
@videolan" sounds snarky in a "i-told-you-so" manner. I think they got the lesson, drawing additional bad light on them is not needed. :-)Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.