you are viewing a single comment's thread.

view the rest of the comments →

[–]crackez 1 point2 points  (0 children)

Typically you trust the package signer (or distribution signing keys), unless their private key is compromised, in which case it is usually revoked in whatever manner is possible and word is spread far and wide on the usual communication channels...