top | item 45195507

(no title)

tstenner | 5 months ago

Or detected easily with package builders like Arg Linux's makepkg that ship a hash along with the source URL. As soon as one user gets a different file, he has an alert and the compromised package for later analysis

discuss

order

untitaker_|5 months ago

like I said, if you assume your adversary is the US government then they might as well start issuing rogue TLS certs to target individuals.