>to trust any number of backdoored https CAs? Just use HTTP Public Key Pinning. It is was killed by Let's Encrypt as an HTTP extension, but nothing prevents you from using a cert preloaded to the device as a package. Of course it may require some modificatikns to apt.
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1464064 Title: Ubuntu apt repos are not available via HTTPS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+bug/1464064/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
