Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #257257

Re: Apt sources.list

From The Wanderer <wanderer@fastmail.fm>
Newsgroups linux.debian.user
Subject Re: Apt sources.list
Date 2023-04-16 01:30 +0200
Message-ID <GkXvb-2ibJ-9@gated-at.bofh.it> (permalink)
References (4 earlier) <GkPHj-2dFR-5@gated-at.bofh.it> <GkR6p-2eno-11@gated-at.bofh.it> <GkSca-2eYe-5@gated-at.bofh.it> <GkX29-2hMw-3@gated-at.bofh.it> <GkXlv-2i8h-5@gated-at.bofh.it>
Organization This space intentionally left blank.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On 2023-04-15 at 19:11, Greg Wooledge wrote:

> On Sat, Apr 15, 2023 at 10:54:10PM +0000, davidson wrote:
> 
>> In case you wish to obscure what software you *install*, but need
>> not conceal the software you *download*:
>> 
>> Step one: Make a list of the packages you want, and then augment
>> it with as many plausible alternatives and red herrings as you
>> like.
>> 
>> Step two: $ apt-get -d install <many packages>
>> 
>> This downloads the packages only, so you can download packages you 
>> will *not* install, along with ones you will. Then install the
>> proper subset you want installed, without the '-d' option.
> 
> I'm at a loss as to what threat model this is supposed to protect
> against.

My guess is that it's supposed to make it harder for people to guess
what exploits your computer may be vulnerable to, by obfuscating which
of the various packages you downloaded are actually installed and
therefore potentially in use.

<snip>

> Now, personally I don't feel this is a threat model that I need to 
> worry about.  I just use plain old http sources at home, and if
> "They" learn that I've downloaded rxvt-unicode and mutt, well, good
> for Them.

My understanding is that mandating HTTPS for all connections is supposed
to make it so that those who might be watching can't treat the choice by
the user to connect via HTTPS as a sign that the user has something to
hide, and therefore is worth observing more closely.

I seem to remember having seen suggestions that some regimes might even
prohibit the use of HTTPS entirely, so as to ensure that they can spy on
their subjects' connections, and that such a prohibition would be less
practical for them to impose if everything requires HTTPS. I'm not sure
about the real-world basis for that, however.

-- 
   The Wanderer

The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man.         -- George Bernard Shaw

Back to linux.debian.user | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 14:20 +0200
  Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 14:30 +0200
    Re: Apt sources.list Greg Wooledge <greg@wooledge.org> - 2023-04-15 15:00 +0200
      Re: Apt sources.list Alain D D Williams <addw@phcomp.co.uk> - 2023-04-15 15:40 +0200
        Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-15 15:50 +0200
          Re: Apt sources.list Alain D D Williams <addw@phcomp.co.uk> - 2023-04-15 16:10 +0200
            Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-15 16:20 +0200
        Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 16:10 +0200
        Re: Apt sources.list Charles Curley <charlescurley@charlescurley.com> - 2023-04-15 16:50 +0200
        Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 17:10 +0200
          Re: Apt sources.list Dan Ritter <dsr@randomstring.org> - 2023-04-15 18:40 +0200
            Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-15 19:50 +0200
              Re: Apt sources.list davidson <davidson@freevolt.org> - 2023-04-16 01:00 +0200
                Re: Apt sources.list Greg Wooledge <greg@wooledge.org> - 2023-04-16 01:20 +0200
                Re: Apt sources.list The Wanderer <wanderer@fastmail.fm> - 2023-04-16 01:30 +0200
                Re: Apt sources.list Stefan Monnier <monnier@iro.umontreal.ca> - 2023-04-16 02:30 +0200
                Re: Apt sources.list davidson <davidson@freevolt.org> - 2023-04-16 02:20 +0200
                Re: Apt sources.list Tim Woodall <debianuser@woodall.me.uk> - 2023-04-16 21:10 +0200
                Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-16 23:00 +0200
                Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-17 03:30 +0200
                Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-17 06:50 +0200
                Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-17 17:10 +0200
                Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-16 07:40 +0200
                Re: Apt sources.list Eduardo M KALINOWSKI <eduardo@kalinowski.com.br> - 2023-04-16 14:10 +0200
          Re: Apt sources.list Alain D D Williams <addw@phcomp.co.uk> - 2023-04-15 20:30 +0200
            Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 20:40 +0200
            Re: Apt sources.list Andy Smith <andy@strugglers.net> - 2023-04-15 22:00 +0200
          Re: Apt sources.list Charles Curley <charlescurley@charlescurley.com> - 2023-04-15 20:50 +0200
          Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-16 02:40 +0200
            Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-16 14:50 +0200
    Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 16:50 +0200
    Re: Apt sources.list "Andrew M.A. Cater" <amacater@einval.com> - 2023-04-15 18:50 +0200
      Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 21:20 +0200
        Re: Apt sources.list "Andrew M.A. Cater" <amacater@einval.com> - 2023-04-15 22:20 +0200
          Re: Apt sources.list songbird <songbird@anthive.com> - 2023-04-16 00:00 +0200
          Re: Apt sources.list Stefan Monnier <monnier@iro.umontreal.ca> - 2023-04-16 06:20 +0200
            Re: Apt sources.list David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 07:00 +0200
            Re: Apt sources.list "Andrew M.A. Cater" <amacater@einval.com> - 2023-04-16 13:20 +0200
              Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-16 16:40 +0200
                Re: Apt sources.list John Hasler <john@sugarbit.com> - 2023-04-16 18:20 +0200
          Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-16 07:20 +0200
            Re: Apt sources.list David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 16:40 +0200
      Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 22:10 +0200
  Re: Apt sources.list Tixy <tixy@yxit.co.uk> - 2023-04-15 18:20 +0200
    Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-15 22:00 +0200
      Re: Apt sources.list Vincent Lefevre <vincent@vinc17.net> - 2023-04-18 16:40 +0200
        Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-18 19:50 +0200
          Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-18 20:00 +0200
            Re: Apt sources.list Vincent Lefevre <vincent@vinc17.net> - 2023-04-20 12:20 +0200
              Re: Apt sources.list Greg Wooledge <greg@wooledge.org> - 2023-04-20 13:30 +0200

csiph-web