• Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 hours ago

    This isn’t true

    Linux package managers typically use GPG which is a much better solution. It is simpler and doesn’t have the unnecessary complexity of certificates.

    What security problems do you think package managers are vulnerable to? If the upstream repo is compromised all bets are off regardless of the system.

    • Mihies@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      7 hours ago

      You are right, GPG signing is good as well. But in both cases you still have unsigned apps.

      What security problems do you think package managers are vulnerable to? If the upstream repo is compromised all bets are off regardless of the system.

      Yep. And in such case an antivirus software might come handy.