From mboxrd@z Thu Jan 1 00:00:00 1970 From: Damien Cassou Subject: bug#39419: On the use of HTTPS for substitute server Date: Wed, 05 Feb 2020 11:34:49 +0100 Message-ID: <877e11gw52.fsf@cassou.me> References: <87v9ombf5r.fsf@cassou.me> <2c0b7fb7-02af-4920-845e-01ac63a8c831@www.fastmail.com> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([2001:470:142:3::10]:59231) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1izI1P-0003T4-Lw for bug-guix@gnu.org; Wed, 05 Feb 2020 05:35:04 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1izI1O-0007Vu-Ew for bug-guix@gnu.org; Wed, 05 Feb 2020 05:35:03 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:39185) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1izI1O-0007VX-B7 for bug-guix@gnu.org; Wed, 05 Feb 2020 05:35:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1izI1O-00087e-7n for bug-guix@gnu.org; Wed, 05 Feb 2020 05:35:02 -0500 Sender: "Debbugs-submit" Resent-Message-ID: In-Reply-To: <2c0b7fb7-02af-4920-845e-01ac63a8c831@www.fastmail.com> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane-mx.org@gnu.org Sender: "bug-Guix" To: Leo Famulari , 39419@debbugs.gnu.org "Leo Famulari" writes: > So, someone who could MITM as could use their > own X.509 certificate and pretend to be that server. IIUC, you agree with me that an attacker can't change the content of packages but can inspect what a user installs. This seems to contradict this paragraph: > HTTPS is recommended because communications are encrypted; conversely, > using HTTP makes all communications visible to an eavesdropper, who > could use the information gathered to determine, for instance, whether > your system has unpatched security vulnerabilities. If you believe the text is good as it is, please just ignore me and close the ticket. Thank you so much for Guix. -- Damien Cassou "Success is the ability to go from one failure to another without losing enthusiasm." --Winston Churchill