I think you're right, and in the meantime concerned persons can just tell their package manager to not follow redirects.
"Therefore, we will know that the issue is fixed in Trisquel when we see
something resembling"
- [Trisquel-users] APT security issue fredo
- Re: [Trisquel-users] APT security issue interxorler
- Re: [Trisquel-users] APT security issue jason
- Re: [Trisquel-users] APT security issue Mason Hock
- [Trisquel-users] Re : APT security issue lcerf
- Re: [Trisquel-users] APT security issue jason
