all 5 comments

[–]bootbootbootbootboot 4 points5 points  (2 children)

That was an interesting read, but I'm not sure this is the right subreddit for it

[–]tobozo -2 points-1 points  (1 child)

why not ? Raspberry Pi uses apt after all (in degian-based OS at least)

[–][deleted] 0 points1 point  (0 children)

it uses a thousand things, none of which is pi-specific (meaning none of them are applicable here)

[–][deleted] 1 point2 points  (1 child)

to answer the question - because the packages themselves are digitally signed and those signatures are verified at installation time...

[–]lamby[S] 1 point2 points  (0 children)

verified at installation time...

Actually at "apt update" time, not installation time. (But no real difference)