Debian: "We don't need to use HTTPS, we sign our packages! Check out whydoesaptnotusehttps[.]com!"
https://lists.debian.org/debian-security-announce/2019/msg00010.html …
https://justi.cz/security/2019/01/22/apt-rce.html …
Oops.
*This* is why you use HTTPS. Defense in depth. Take note @videolan.
-
-
Of course but way more effort than just taking note of every single package and version downloaded by HTTPS and therefore way more easy to profile and create targets.
-
I meant by HTTP, my mind auto corrects it.
End of conversation
New conversation -
-
-
Https could also allow easy usage of HTTP/2 with multiplexing & pipelining making traffic analysis a LOT harder
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.