[Bug 1186793] Re: Updating is over insecure connection

2019-01-30 Thread Andy Brody
** Changed in: ubuntu Status: Expired => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1186793 Title: Updating is over insecure connection To manage notifications about this bug

[Bug 1186793] Re: Updating is over insecure connection

2018-08-07 Thread Marco Voelz
Any thoughts on https://blog.packagecloud.io/eng/2018/02/21/attacks-against-secure-apt-repositories/ ? Seems like there are a few good reasons to using TLS, wdyt? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1186793] Re: Updating is over insecure connection

2017-07-04 Thread Robie Basak
> How do gpg signatures and SHA512 sums help with other people in the open WLAN or between I and the mirror being able to see what exactly I download or update? HTTPS wouldn't protect you either. The sizes and dependency trees of individual packages are well-known. If I could see your HTTPS apt

[Bug 1186793] Re: Updating is over insecure connection

2016-03-21 Thread Launchpad Bug Tracker
[Expired for Ubuntu because there has been no activity for 60 days.] ** Changed in: ubuntu Status: Incomplete => Expired -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1186793 Title:

[Bug 1186793] Re: Updating is over insecure connection

2016-01-21 Thread Dimitri John Ledkov
Please let me know if you have further concerns. ** Changed in: ubuntu Status: Confirmed => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1186793 Title: Updating is over insecure

[Bug 1186793] Re: Updating is over insecure connection

2016-01-21 Thread Dimitri John Ledkov
We do not provide a default way to receive updates in a private manner. However, one can arrange private methods of doing so. Create an ubuntu mirror via an out-of-bound connection and point your machines there, thus not exposing update traffic to a monitored connection. After establishing an

[Bug 1186793] Re: Updating is over insecure connection

2016-01-21 Thread Dimitri John Ledkov
= Updates = Ubuntu downloads updates over http by default, however that is not insecure. This is because all those updates are validated with GPG against the keys that are already on the system in the ubuntu-keyring package. The signatures on our updates are strong, bashed on SHA512 checksums at

[Bug 1186793] Re: Updating is over insecure connection

2016-01-21 Thread Mikaela Suomalainen
How do gpg signatures and SHA512 sums help with other people in the open WLAN or between I and the mirror being able to see what exactly I download or update? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1186793] Re: Updating is over insecure connection

2014-10-24 Thread Matthew Paul Thomas
This requires more than just switching to HTTPS. The updates UI will also need to explain HTTPS failures in such a way that users don't seek insecure workarounds. Windows updates are being subjected to MITM patches. Windows Update correctly fails to install them, but gives a vague error code.

[Bug 1186793] Re: Updating is over insecure connection

2014-08-22 Thread Matthew Paul Thomas
Fixing this might depend on bug 1185159 and/or bug 1209292. ** Description changed: Relying on signatures is silly. It gives attackers much more control over a situation, and we already know that this *doesn't work* when weak signatures like MD5 are used (see Flame hash collision). Is the

[Bug 1186793] Re: Updating is over insecure connection

2013-06-04 Thread Colin O'Brien
** This bug is no longer a duplicate of bug 247445 Package managers vulnerable to replay and endless data attacks -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1186793 Title: Updating is over

[Bug 1186793] Re: Updating is over insecure connection

2013-06-03 Thread Nick Rhodes
*** This bug is a duplicate of bug 247445 *** https://bugs.launchpad.net/bugs/247445 ** This bug has been marked a duplicate of bug 247445 Package managers vulnerable to replay and endless data attacks -- You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 1186793] Re: Updating is over insecure connection

2013-06-03 Thread Chris Thompson
*** This bug is a duplicate of bug 247445 *** https://bugs.launchpad.net/bugs/247445 The linked bug is not a duplicate of this one. That bug was for the replay and endless data attacks posed in the Stork work. This bug is that the repositories are not served over HTTPS, which is another issue

[Bug 1186793] Re: Updating is over insecure connection

2013-06-03 Thread Colin O'Brien
*** This bug is a duplicate of bug 247445 *** https://bugs.launchpad.net/bugs/247445 Like Chris Thompson said, completely different bug report. Not a duplicate. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1186793] Re: Updating is over insecure connection

2013-06-02 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: ubuntu Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1186793 Title: Updating is

[Bug 1186793] Re: Updating is over insecure connection

2013-06-02 Thread Ubuntu Foundations Team Bug Bot
Thank you for taking the time to report this bug and helping to make Ubuntu better. It seems that your bug report is not filed about a specific source package though, rather it is just filed against Ubuntu in general. It is important that bug reports be filed about source packages so that people

[Bug 1186793] Re: Updating is over insecure connection

2013-06-02 Thread Colin O'Brien
I tried assigning ia32-apt-get but it says it isn't a package in Ubuntu. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1186793 Title: Updating is over insecure connection To manage notifications