Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is that any more secure than just providing a download?


It's not at the time of installation, but prior to updates the package management system will check signatures of the packages. (And it will only accept packages signed with your key, so the attack used against Transmission wouldn't work)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: