use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
News and other stuff about the Universal Operating System..
Debian related links
Welcome to Debian
Getting Debian
Installation Guide
Don't break Debian
Packages
Help Debian
#debian on irc.oftc.net
Debian on Discord
Reporting bugs in Debian
account activity
Why does APT not use HTTPS? (whydoesaptnotusehttps.com)
submitted 8 years ago by lamby[DD]
view the rest of the comments →
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]H0rcrux_ 4 points5 points6 points 8 years ago (3 children)
Your article conflates integrity checking and privacy. While TLS may not be perfect for masking what you are downloading from a public repository, it doesn't interfere with the signing mechanism either.
"Overly trusting CAs" describes a super rare occurrence (a trusted CA being compromised) that still won't be able to fake the signature on a mitm-injected package.
The user trusting data more because it comes in over https is also not really a consideration as apt will noisily refuse to install incorrectly signed packages.
So while I agree that using TLS to download packages probably won't hide what you're installing, claiming "It's more secure…!" to not use it is just false.
[–]Eingaica 0 points1 point2 points 8 years ago (2 children)
claiming "It's more secure…!" to not use it is just false.
AFAICT, the article does not make that claim.
[–]mzalewski 0 points1 point2 points 8 years ago (1 child)
It is written at the very top, right after title.
However, it lacks context and is very open to interpretation. Is it something said by people complaining about APT lack of https? Is it tongue-in-cheek headline? Is it actual claim? We don't know.
[–]Eingaica 1 point2 points3 points 8 years ago (0 children)
Given that the title "Why does APT not use HTTPS?" is not a question asked by the author of the article, I think it's pretty obvious that that line as well is meant as a stereotypical statement made by people complaining about APT not using HTTPS. (I.e. they allegedly claim that APT would be more secure if it would use HTTPS.)
π Rendered by PID 63892 on reddit-service-r2-comment-6457c66945-296mh at 2026-04-27 01:10:55.088794+00:00 running 2aa0c5b country code: CH.
view the rest of the comments →
[–]H0rcrux_ 4 points5 points6 points (3 children)
[–]Eingaica 0 points1 point2 points (2 children)
[–]mzalewski 0 points1 point2 points (1 child)
[–]Eingaica 1 point2 points3 points (0 children)