this post was submitted on 06 Aug 2024
33 points (97.1% liked)

Cybersecurity

5948 readers
123 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

DNS poisoning attack worked even when targets used DNS from Google and Cloudflare.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 9 points 5 months ago (2 children)

One more reason to have centralized and secure way to do app updates like in Linux (yes, you could still get f for example with not signed app images and such, but less likely)

Not allowing every single app maker make their own update center is the way to go.

[–] sugar_in_your_tea 4 points 5 months ago* (last edited 5 months ago)

Less central repo, and more signed packages. I don't care where my packages come from, I just care that they're signed and verified on the client. I can use any mirror I want, including the one I self-host, and I'll get the same result. Then the problem changes to making sure your mirror is in sync, and that shouldn't be that hard.

[–] [email protected] 3 points 5 months ago (1 children)

At that point it's a single point of failure, hack that central repo and infect everything. Plus Linux is not centralized... That's kinda the point, suse, Debian, arch, red hat all have their own repos....

[–] [email protected] 3 points 5 months ago* (last edited 5 months ago)

Yes, but you as a user are in control of when/how you update, you can first update some test server and only then propagate it to other.

But still better have single (hopefully secure) risk point/target that you need to pay attention than have multiple god know when/how updating that you dont even dont know about.