• 0 Posts
  • 92 Comments
Joined 7 months ago
cake
Cake day: October 6th, 2024

help-circle
  • Package managers like apt use cryptography to check signatures in everything they download to make sure they aren’t malicious.

    Docket doesn’t do this. They have a system called DCT but its horribly broken (not to mention off by default).

    So when you run docker pull, you can’t trust anything it downloads.