sweng

joined 1 year ago
[–] sweng@programming.dev 1 points 5 months ago* (last edited 5 months ago) (4 children)

I'm confused why you think it would be anything else, and why you are so dead set on this. Repos include a signing key. There is an option to skip signature checking. And you think that signature checking is not used during downloads, despite this?

Ok, here are a few issues related to signatures being checked by default, when downloading: https://github.com/flatpak/flatpak/issues/4836 https://github.com/flatpak/flatpak/issues/5657 https://github.com/flatpak/flatpak/issues/3769 https://github.com/flatpak/flatpak/issues/5246 https://askubuntu.com/questions/1433512/flatpak-cant-check-signature-public-key-not-found https://stackoverflow.com/questions/70839691/flatpak-not-working-apparently-gpg-issue

Flatpak repos are signed and the signature is checked when downloading.

It's OK to be wrong. Dying on this hill seems pretty weird to me.

[–] sweng@programming.dev 1 points 5 months ago* (last edited 5 months ago) (6 children)

From the page:

It is recommended that OSTree repositories are verified using GPG whenever they are used. However, if you want to disable GPG verification, the --no-gpg-verify option can be used when a remote is added.

That is talking about downloading as well. Yes, you can turn it off, but so can you usually do it with native package managers, e.g. pacman: https://wiki.archlinux.org/title/Pacman/Package_signing

[–] sweng@programming.dev 4 points 5 months ago (10 children)

In what way don't they "securely download" ?

[–] sweng@programming.dev 24 points 9 months ago (1 children)

Why host it locally in that case, and why host it on a Pi? Seems rather restrictive for that usecase.

view more: ‹ prev next ›