Possibly, possibly not. One way to hide it would be to modify the update reminder program to pretend to download updates, or to point to a different APT repository. It doesn't matter; they're vulnerable to whatever malicious features have been added in the meantime.

I don't think you fully comprehend how much of a security hole this would be. Maybe an analogy would help: allowing anyone to change what updates are sent to users would be almost as bad as leaving an SSH port open and telling everyone what your password is in the hope that someone is going to come along and fix your security problems. It's completely insane.

Reply via email to