tproenca / pmsarm7

Plex Media Server ARM package for Debian/Ubuntu Linux
https://tproenca.github.io/pmsarm7
25 stars 5 forks source link

Repository not signed. #8

Closed Jorricks closed 5 years ago

Jorricks commented 7 years ago

Hello,

You provided an awesome project however it is very insecure. This is because your repository is not signed. The packages can therefore not be authenticated and the computer is vulnerable to a MITM attack. Would you mind to try to make it signed :)?

lorenzschmid commented 6 years ago

I'm not sure if it is wise to post a workaround but if you are aware of what you are doing: Add [trusted=yes] in front of the package URL in the source list, i.e.

echo "deb [trusted=yes] http://dl.bintray.com/tproenca/pmsarm7 jessie main" | sudo tee /etc/apt/sources.list.d/pms.list

For more details see this answer.

tproenca commented 5 years ago

Actually, the repository supportshttps. I just changed the documentation.