How secure are third party Ubuntu (APT) repository mirrors

Posted by bakytn on Server Fault See other posts from Server Fault or by bakytn
Published on 2011-02-20T07:19:27Z Indexed on 2011/02/20 7:26 UTC
Read the original article Hit count: 282

Filed under:
|
|
|

Hello! We have locally an Ubuntu mirrors to save a lot of traffic (our external traffic is not free)

So whenever I apt-get install "program" it gets from that repository.

the question is...basically they can substitute any package with their own?

So it's 100% on my own risk and I can be hacked easily on any apt-get upgrade or a-g install or a-g dist-upgrade?

for example the very basic ones like "telnet" or any other.

© Server Fault or respective owner

Related posts about ubuntu

Related posts about security