Re: Do Synaptic, Aptitude and Adept use secure-apt?



Priam wrote:
J.O. Aho wrote:
Priam wrote:
I'm thinking about moving either to Debian or Kubuntu. Does anyone know
if Synaptic, Aptitude and Adept use secure-apt? Is there an apt-get and
a secure apt, or are all versions of apt now secure?

A simple search at google gave this:

In recent releases, Debian has been using strong crypto to validate
downloaded
packages. This is commonly called "secure apt" (or "apt-secure") and was
implemented in Apt version 0.6 in 2003, which Debian migrated to in 2005.

I guess that answers your question

So, apt is now all secure-apt. My concern arose when I saw Adpet working
in Kubuntu. When you click "details" you see the packages being
downloaded, then installed. Nowhere do you see that they're checked,
MD5SUMs and signatures.

You should see that when the package in question fails the md5sum check.

There are distros that uses even more advanced hashes to check the validy of
the package, even with multiple hashes, which makes it even more difficult to
make a false package.


--

//Aho
.



Relevant Pages

  • Re: Debian
    ... Both apt and dpkg are package tools, as are aptitude, synaptic, ... Which is ultimately why Ubuntu, and via Ubuntu, Debian, is basically ... There have been lots of efforts to "improve" Debian before now, ...
    (Ubuntu)
  • APT -- if I do this will I screw the pooch?
    ... I typically use aptitude in command-line mode as a front-end to APT. ... I was thinking of setting up the notebook by doing a basic install off my old woody CDs I originally set up my desktop off of, getting a working net connection in place, then immediately upgrading everything via the net to current stable before building out the system any further. ... I don't want the notebook to have to download them all again, especially since security.debian.org, which has a lot of the latest versions of stable packages, seems to get overloaded and be very slow to download at times. ... This is because although I want them both to use the same repository of downloaded package files, I want the two machines to independently track what's installed, so I don't have to keep installed packages identical on both machines. ...
    (Debian-User)
  • Re: eclipse-pydev: New upstream release 1.3.13 avaible
    ... [general package management] ... I strongly disagree with having maven listed in a row with apt and rpm ... lot of internal java dev teams I know of still deal with dependencies by ... other package needs a newer version. ...
    (Ubuntu)
  • Re: smart package mgr question?
    ... resolving broken package deps inside of an installed system. ... apt and smart diagnose them and try to resolve them, ... I.e. the fact yum doesn't complain, ... I have run into problems where apt tries to fix the repository issues ...
    (Fedora)
  • Re: [SLE] apt-get questions
    ... > each have some duplicates of packages of the others. ... Unless they made some changes to apt in the past few months, ... written to see that it can get the same package at another place. ...
    (SuSE)