How to fix it
How to fix it
Posted Jul 17, 2008 16:48 UTC (Thu) by justincappos (guest, #52950)In reply to: How to fix it by epa
Parent article: Study: Attacks on package managers
There is an additional problem with BitTorrent or other P2P solutions that hasn't been mentioned in the discussion here. When you download the current version of a package, you are commonly doing so because you are upgrading an old version. So when downloading a package from an untrusted party (like a mirror) you disclose that you are running outdated software to that party. This is obviously bad because they may be able to root you, etc. Using something like BitTorrent increases the effect because now a much larger group of people with a lower barrier to entry are aware of you requesting a package. I don't think this is a good trade-off given the current status quo.