How secure are third party Ubuntu (APT) repository mirrors
- by bakytn
Hello! We have locally an Ubuntu mirrors to save a lot of traffic (our external traffic is not free)
So whenever I apt-get install "program" it gets from that repository.
the question is...basically they can substitute any package with their own?
So it's 100% on my own risk and I can be hacked easily on any apt-get upgrade
or a-g install or a-g dist-upgrade?
for example the very basic ones like "telnet" or any other.