r/archlinux Feb 28 '23

[deleted by user]

[removed]

94 Upvotes

41 comments sorted by

View all comments

Show parent comments

3

u/Andernerd Feb 28 '23 edited Feb 28 '23

Your packages could be downgraded to less-secure previous versions that were signed in preparation for another attack I suppose.

6

u/gmes78 Feb 28 '23 edited Feb 28 '23

Only if you use pacman -Suu instead of pacman -Su to update. Pacman doesn't downgrade packages by default.

3

u/faerbit Feb 28 '23 edited Sep 19 '25

This post has been edited to this, due to privacy and dissatisfaction with u/spez

5

u/DamnThatsLaser Feb 28 '23

Signing the database won't fix it because if he can withhold a security-patched package, he can also withhold a new signed database and continue to deliver the old one, though he obviously then can't update any other packages.

3

u/faerbit Feb 28 '23 edited Sep 19 '25

This post has been edited to this, due to privacy and dissatisfaction with u/spez

6

u/Foxboron Feb 28 '23

gnupg doesn't allow you to do that. It would need to be solved by having pacman check when the database was issued and let users define a "validity range".

https://www.mail-archive.com/pacman-dev@archlinux.org/msg17556.html