Is there anything going to be done about the information disclosure problem? Is there
anything that CAN be done about the information disclosure?
HTTPS connects can stop random points from noticing a host asking for an update but that won't
stop a mirror site itself from realizing that by asking for a package it means the requester
is running a previous version and is vulnerable. Even a mirror on a 'reputable' network can
itself be compromised. In the end the whole concept of mirrors depends on trusting unknown
machines. Crypto can mitigate some of the more gross dangers but leaves a false sense of
security regarding more subtle risks.