@library_napper@monyet.cc avatar

library_napper

@library_napper@monyet.cc

This profile is from a federated server and may be incomplete. Browse more on the original instance.

library_napper,
@library_napper@monyet.cc avatar

Its more secure to go through a package manager. Checking signatures is important.

library_napper,
@library_napper@monyet.cc avatar

Yes, there is. You’re risking downloading malicious software.

library_napper,
@library_napper@monyet.cc avatar

They probably lowered it became mullvad is a security company and downlaoing .deb files from the Internet ia a vector for attack

library_napper,
@library_napper@monyet.cc avatar

More Performant, yes. More Secure? Not sure about that

library_napper,
@library_napper@monyet.cc avatar

ChatGPT is garbage in garbage out. It’ll probably tell you to curl a file off the internet and pipe it to bash as root.

library_napper,
@library_napper@monyet.cc avatar

You might want to say why or you’ll get downvoted. Spoiler: its not safe and this is how you get malicious software on your computer

library_napper,
@library_napper@monyet.cc avatar

Homebrew is extremely insecure. It doesn’t verify package signatures, so its just as bad as the “just donloaf some sketchy untrusted binary off a website” approach

library_napper,
@library_napper@monyet.cc avatar

Https is vulnerable to loads of attack. That’s why we sign packages.

library_napper,
@library_napper@monyet.cc avatar

No, you’re confusing two vectors of attack. I’m saying that if you fan trust the vendor, then you’re still at risk from downloading malicious software that was manipulated between the vendor and you (man in the middle attack), unless you verified a signature using a key stores offline (note https is still vulnerable because the keys are stored online)

library_napper, (edited )
@library_napper@monyet.cc avatar

That’s why you download the key from multiple distinct domains from multiple distinct locations using multiple distinct devices and veryify their fingerprints match. If the key/fingerprint is only available on one domain, open a bug report with the maintainer.

library_napper, (edited )
@library_napper@monyet.cc avatar

Of course it matters.We dont want to support or contribute content to a service that could go down one day and all the data is lost because we can’t fork it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #