[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Q: Use https for {deb,security}.debian.org by default



On 8/20/21 2:37 PM, Simon Richter wrote:

This is a use case where HTTPS does hurt, and where I can't think of any good mitigation strategies that wouldn't be worse from a security PoV than the status quo.

Such situations are the exception rather than the norm. If https is detrimental to their setup, they can choose to opt out of it.

For everyone else, I think https should be the default.

Kyle


Reply to: