▲ 407 ▼ Flathub now marks unverified apps (lemmy.ml) submitted 2 years ago by mr_MADAFAKA@lemmy.ml to c/linux@lemmy.ml 67 comments fedilink hide all child comments
[–] delirious_owl@discuss.online -1 points 2 years ago (1 child) Nope. Link me to the docs that say this. permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) The GPG key is literally in the repo file https://dl.flathub.org/repo/flathub.flatpakrepo permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online -1 points 2 years ago (1 child) Lol that's not for signing the packages permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) There is no such thing as a “package”. It is a repository of binary data with references to data in it (ala git). The whole repo and all data is gpg signed. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago* (1 child) Your claim that package payloads are signed is bullshit. Back it up by citing your sources permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) > ostree show flathub:runtime/org.kde.Platform/x86_64/6.6 commit a7443e846cf67d007fcecda5c9dc27844001cfb8929064395cfc25c6d71d9474 Parent: 23107550082daf3b2892a4a0db2543838578ca882340a756b988bc5c1614540c ContentChecksum: 607ba9475d32a24c51509bc7919f5a93d401f8f7198c30ad93ad74051d966c41 Date: 2024-01-30 13:55:08 +0000 build of org.kde.Sdk, Tue Jan 30 11:23:00 UTC 2024 (5998d2f3ef21414d14f066ab91fa44e5aef65b90) Name: org.kde.Platform Arch: x86_64 Branch: 6.6 Built with: Flatpak 1.14.4 Found 1 signature: Signature made Tue 30 Jan 2024 12:21:18 PM CST using RSA key ID 562702E9E3ED7EE8 Good signature from "Flathub Repo Signing Key <flathub@flathub.org>" Primary key ID 4184DD4D907A7CAE Key expires Mon 14 Jun 2027 08:19:40 AM CDT Primary key expires Mon 14 Jun 2027 08:18:56 AM CDT permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago (1 child) And what happens if I mitm you and you get something unsigned? Does it ignore it and proceed? This is why in asking for the docs that describe the security permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] AProfessional@lemmy.world 1 point 2 years ago (1 child) The GPG key is literally in the repo file https://dl.flathub.org/repo/flathub.flatpakrepo permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online -1 points 2 years ago (1 child) Lol that's not for signing the packages permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) There is no such thing as a “package”. It is a repository of binary data with references to data in it (ala git). The whole repo and all data is gpg signed. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago* (1 child) Your claim that package payloads are signed is bullshit. Back it up by citing your sources permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) > ostree show flathub:runtime/org.kde.Platform/x86_64/6.6 commit a7443e846cf67d007fcecda5c9dc27844001cfb8929064395cfc25c6d71d9474 Parent: 23107550082daf3b2892a4a0db2543838578ca882340a756b988bc5c1614540c ContentChecksum: 607ba9475d32a24c51509bc7919f5a93d401f8f7198c30ad93ad74051d966c41 Date: 2024-01-30 13:55:08 +0000 build of org.kde.Sdk, Tue Jan 30 11:23:00 UTC 2024 (5998d2f3ef21414d14f066ab91fa44e5aef65b90) Name: org.kde.Platform Arch: x86_64 Branch: 6.6 Built with: Flatpak 1.14.4 Found 1 signature: Signature made Tue 30 Jan 2024 12:21:18 PM CST using RSA key ID 562702E9E3ED7EE8 Good signature from "Flathub Repo Signing Key <flathub@flathub.org>" Primary key ID 4184DD4D907A7CAE Key expires Mon 14 Jun 2027 08:19:40 AM CDT Primary key expires Mon 14 Jun 2027 08:18:56 AM CDT permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago (1 child) And what happens if I mitm you and you get something unsigned? Does it ignore it and proceed? This is why in asking for the docs that describe the security permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] delirious_owl@discuss.online -1 points 2 years ago (1 child) Lol that's not for signing the packages permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) There is no such thing as a “package”. It is a repository of binary data with references to data in it (ala git). The whole repo and all data is gpg signed. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago* (1 child) Your claim that package payloads are signed is bullshit. Back it up by citing your sources permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) > ostree show flathub:runtime/org.kde.Platform/x86_64/6.6 commit a7443e846cf67d007fcecda5c9dc27844001cfb8929064395cfc25c6d71d9474 Parent: 23107550082daf3b2892a4a0db2543838578ca882340a756b988bc5c1614540c ContentChecksum: 607ba9475d32a24c51509bc7919f5a93d401f8f7198c30ad93ad74051d966c41 Date: 2024-01-30 13:55:08 +0000 build of org.kde.Sdk, Tue Jan 30 11:23:00 UTC 2024 (5998d2f3ef21414d14f066ab91fa44e5aef65b90) Name: org.kde.Platform Arch: x86_64 Branch: 6.6 Built with: Flatpak 1.14.4 Found 1 signature: Signature made Tue 30 Jan 2024 12:21:18 PM CST using RSA key ID 562702E9E3ED7EE8 Good signature from "Flathub Repo Signing Key <flathub@flathub.org>" Primary key ID 4184DD4D907A7CAE Key expires Mon 14 Jun 2027 08:19:40 AM CDT Primary key expires Mon 14 Jun 2027 08:18:56 AM CDT permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago (1 child) And what happens if I mitm you and you get something unsigned? Does it ignore it and proceed? This is why in asking for the docs that describe the security permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] AProfessional@lemmy.world 1 point 2 years ago (1 child) There is no such thing as a “package”. It is a repository of binary data with references to data in it (ala git). The whole repo and all data is gpg signed. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago* (1 child) Your claim that package payloads are signed is bullshit. Back it up by citing your sources permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) > ostree show flathub:runtime/org.kde.Platform/x86_64/6.6 commit a7443e846cf67d007fcecda5c9dc27844001cfb8929064395cfc25c6d71d9474 Parent: 23107550082daf3b2892a4a0db2543838578ca882340a756b988bc5c1614540c ContentChecksum: 607ba9475d32a24c51509bc7919f5a93d401f8f7198c30ad93ad74051d966c41 Date: 2024-01-30 13:55:08 +0000 build of org.kde.Sdk, Tue Jan 30 11:23:00 UTC 2024 (5998d2f3ef21414d14f066ab91fa44e5aef65b90) Name: org.kde.Platform Arch: x86_64 Branch: 6.6 Built with: Flatpak 1.14.4 Found 1 signature: Signature made Tue 30 Jan 2024 12:21:18 PM CST using RSA key ID 562702E9E3ED7EE8 Good signature from "Flathub Repo Signing Key <flathub@flathub.org>" Primary key ID 4184DD4D907A7CAE Key expires Mon 14 Jun 2027 08:19:40 AM CDT Primary key expires Mon 14 Jun 2027 08:18:56 AM CDT permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago (1 child) And what happens if I mitm you and you get something unsigned? Does it ignore it and proceed? This is why in asking for the docs that describe the security permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] delirious_owl@discuss.online 0 points 2 years ago* (1 child) Your claim that package payloads are signed is bullshit. Back it up by citing your sources permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) > ostree show flathub:runtime/org.kde.Platform/x86_64/6.6 commit a7443e846cf67d007fcecda5c9dc27844001cfb8929064395cfc25c6d71d9474 Parent: 23107550082daf3b2892a4a0db2543838578ca882340a756b988bc5c1614540c ContentChecksum: 607ba9475d32a24c51509bc7919f5a93d401f8f7198c30ad93ad74051d966c41 Date: 2024-01-30 13:55:08 +0000 build of org.kde.Sdk, Tue Jan 30 11:23:00 UTC 2024 (5998d2f3ef21414d14f066ab91fa44e5aef65b90) Name: org.kde.Platform Arch: x86_64 Branch: 6.6 Built with: Flatpak 1.14.4 Found 1 signature: Signature made Tue 30 Jan 2024 12:21:18 PM CST using RSA key ID 562702E9E3ED7EE8 Good signature from "Flathub Repo Signing Key <flathub@flathub.org>" Primary key ID 4184DD4D907A7CAE Key expires Mon 14 Jun 2027 08:19:40 AM CDT Primary key expires Mon 14 Jun 2027 08:18:56 AM CDT permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago (1 child) And what happens if I mitm you and you get something unsigned? Does it ignore it and proceed? This is why in asking for the docs that describe the security permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] AProfessional@lemmy.world 1 point 2 years ago (1 child) > ostree show flathub:runtime/org.kde.Platform/x86_64/6.6 commit a7443e846cf67d007fcecda5c9dc27844001cfb8929064395cfc25c6d71d9474 Parent: 23107550082daf3b2892a4a0db2543838578ca882340a756b988bc5c1614540c ContentChecksum: 607ba9475d32a24c51509bc7919f5a93d401f8f7198c30ad93ad74051d966c41 Date: 2024-01-30 13:55:08 +0000 build of org.kde.Sdk, Tue Jan 30 11:23:00 UTC 2024 (5998d2f3ef21414d14f066ab91fa44e5aef65b90) Name: org.kde.Platform Arch: x86_64 Branch: 6.6 Built with: Flatpak 1.14.4 Found 1 signature: Signature made Tue 30 Jan 2024 12:21:18 PM CST using RSA key ID 562702E9E3ED7EE8 Good signature from "Flathub Repo Signing Key <flathub@flathub.org>" Primary key ID 4184DD4D907A7CAE Key expires Mon 14 Jun 2027 08:19:40 AM CDT Primary key expires Mon 14 Jun 2027 08:18:56 AM CDT permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago (1 child) And what happens if I mitm you and you get something unsigned? Does it ignore it and proceed? This is why in asking for the docs that describe the security permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] delirious_owl@discuss.online 0 points 2 years ago (1 child) And what happens if I mitm you and you get something unsigned? Does it ignore it and proceed? This is why in asking for the docs that describe the security permalink fedilink source parent hideshow 2 child comments replies: [–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] AProfessional@lemmy.world 1 point 2 years ago (1 child) GPG errors are fatal unless you manually configure the repo to ignore them with an obscure command. permalink fedilink source parent hideshow 2 child comments replies: [–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent
[–] delirious_owl@discuss.online 0 points 2 years ago Please link to the docs permalink fedilink source parent