How secure are third party Ubuntu (APT) repository mirrors
Posted
by
bakytn
on Server Fault
See other posts from Server Fault
or by bakytn
Published on 2011-02-20T07:19:27Z
Indexed on
2011/02/20
7:26 UTC
Read the original article
Hit count: 345
Hello! We have locally an Ubuntu mirrors to save a lot of traffic (our external traffic is not free)
So whenever I apt-get install "program" it gets from that repository.
the question is...basically they can substitute any package with their own?
So it's 100% on my own risk and I can be hacked easily on any apt-get upgrade or a-g install or a-g dist-upgrade?
for example the very basic ones like "telnet" or any other.
© Server Fault or respective owner