Hmm, it's almost as if the author of https://whydoesaptnotusehttps.com/ may have overlooked a few things.
I think I understand the exploit but I don't understand whether apt using https would prevent it or not. The author says: > Yes, a malicious mirror could still exploit a bug like this, even with https. and: > I wouldn’t have been able to exploit the Dockerfile at the top of this post if the default package servers had been using https. So which is it?
HTTP: Everyone can pwn you.
Not saying the first one is ideal, but the second one is definitely worse.