Debian: "We don't need to use HTTPS, we sign our packages! Check out whydoesaptnotusehttps[.]com!"
https://lists.debian.org/debian-security-announce/2019/msg00010.html …
https://justi.cz/security/2019/01/22/apt-rce.html …
Oops.
*This* is why you use HTTPS. Defense in depth. Take note @videolan.
-
-
This Tweet is unavailable.
-
the sane proposal would be to default to https mirrors only by default, and allow people to choose less secure mirrors at their leisure. but https is a solved problem, and outside of apathy there's absolutely no reason to host an http-only content mirror in 2019
0 replies 0 retweets 1 like -
This Tweet is unavailable.
-
Telling all your mirrors "HTTPS will be required starting on this date" is not rocket science. It's 2019, if you can't set up Let's Encrypt you shouldn't be running a mirror.
1 reply 0 retweets 5 likes -
This Tweet is unavailable.
Being rude in your bug tracker is a *great* way to put me off contributing to your project.
8:28 AM - 22 Jan 2019
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.