Quantcast
Channel: Raspberry Pi Forums
Viewing all articles
Browse latest Browse all 2526

Raspberry Pi OS • Is using https in APT really as simple as changing http to https in the apt sources list?

$
0
0
so

Code:

sudo nano /etc/apt/sources.list
and changing all http to https is really all I need to do or am I missing something? Why isn't this the default?

There has been atleast 2 serious remote code execution exploits found in apt because of buggy package verification. That could have been prevented by using https.
links to the security bulletins
https://www.debian.org/security/2016/dsa-3733
https://www.debian.org/security/2019/dsa-4371

Is there any plan to make https the default in the future?

Statistics: Posted by twostarl — Fri May 17, 2024 1:36 pm



Viewing all articles
Browse latest Browse all 2526

Trending Articles