Repos do not default to HTTPS, unless you can point to a patch that shows they do. Security depends heavily on defaults decided by maintainers, before it falls to ornate user and administrator decisions. The shift in responsibility is problematic. I don't see how the CVE potential is resolved, almost a decade after this report.
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1464064 Title: Ubuntu apt repos are not available via HTTPS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+bug/1464064/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs