• Mihies@programming.dev
    link
    fedilink
    arrow-up
    1
    arrow-down
    2
    ·
    16 hours ago

    You are right, GPG signing is good as well. But in both cases you still have unsigned apps.

    What security problems do you think package managers are vulnerable to? If the upstream repo is compromised all bets are off regardless of the system.

    Yep. And in such case an antivirus software might come handy.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      8 hours ago

      Antivirus software would be totally useless since the problem is your own system.

      There is also the issue of trust in the antivirus. This programs are typically high privilege and mostly snake oil.