Re: holes in secure apt

On Thu, 2014-06-12 at 19:43 +0100, Wookey wrote: 
> So it does default to signed downloads and SFAIK will always do this
> wether or not any keys are installed/available, unless explicitly disabled.
What I meant was the discussion here:

i.e. different behaviour depending on whether debian-archive-keyring is
installed or not.


