On 22/10/2025 19:34, Hendrik Visage wrote:
>
>
>> On 22 Oct 2025, at 19:26, Bernard Rosset <bernard+devuan@???> wrote:
>>
>> I see there is a different list for HTTP mirrors and it makes me wonder: isn't serving files over HTTP problematic? Contrary to the APT protocol, there is no embedded GPG signature check.
>
> To S or not to S, that is the HTTP
>
> Once you have the GPG keys downloaded, the DEB packages are checked by those keys as authentic from the package maintainer.
>
> That is a much more secure and trustable mechanism, than httpS where a compromised server is worse ‘cause now you implicitly trusted the source server…. besides CAs had been shown in the past to not be as trustable in any case, but lets not debate that, but the core issue: DEBs are secured by the signatures of the repo and package maintainer’s PGP/GPG keys that had not been compromised.
This… is a description of the APT protocol I underlined.
My point was: HTTP is acceptable there thanks to client-side
integrity/authentication check (even if I would still question its
benefits ending up counting beans about TLS overhead).
Let's not start the debate on server compromission and GPG keys
security, which would be off-topic here, even though it's debatable, and
those debates never end in an ol' round, round circle fashion.
Unless manual care is taken with HTTP, there is no such thing. At least
TLS secures against channel attack (for CAs part of the list you use/trust).
My point was: raw HTTP without even TLS is the absolute worst case, and
setting up a TLS certificate these days is accessible.
Why actively promoting it, leading to encouraging it?
If mirrors can't handle it, let's make it the exception, but why not
asking for mirrors to provide files over HTTPS and to ensure HTTP ->
HTTPS redirection?
Bernard (Beer) Rosset
https://rosset.net/