how to update mobian over tor
#11
How can we trust those TOR links not to contain malware? I would recommend HTTPS instead, failing that HTTP, but not TOR with Onion links given by some random commenter on some forum.
  Reply
#12
(07-09-2023, 05:40 AM)Kevin Kofler Wrote: How can we trust those TOR links not to contain malware? I would recommend HTTPS instead, failing that HTTP, but not TOR with Onion links given by some random commenter on some forum.

we should be suspicious of tor links. however, if signing keys are properly validated, then installer won't install those altered packages.

this creates another problem, where are signing keys from!? do users check signing keys!?

btw, http (non-ssl) could be hijacked in rare cases.
  Reply
#13
(07-09-2023, 03:27 PM)zetabeta Wrote: btw, http (non-ssl) could be hijacked in rare cases.
Which is why I recommend HTTPS if possible. But Debian has this strange idea of still defaulting to unencrypted HTTP mirrors in 2023 and requiring a subpackage to be installed for APT to support HTTPS at all.
  Reply
#14
(07-09-2023, 05:40 AM)Kevin Kofler Wrote: How can we trust those TOR links not to contain malware? I would recommend HTTPS instead, failing that HTTP, but not TOR with Onion links given by some random commenter on some forum.

links not random not suspicious. all  .onion  links in this thread are official debian mirrors https://onion.debian.org  as zetabeta says, non official mirrors okay if signing keys are properly validated, then installer won't install those altered packages.  But all onion links in this thread are official debian mirrors https://onion.debian.org

sub packages no longer need to be installed for apt transport https support
  Reply
#15
Updated trixie instructions

Code:
sudo apt install apt-transport-tor  tor

 Edit  /etc/apt/sources.list  as root

Code:
sudo nano  /etc/apt/sources.list   

Put # in front of every existing line and add these two new lines


Code:
deb  tor://2s4yqjx5ul6okpp3f2gaunr2syex5jgbfpfvhxxbbjwnrsvbk5v3qbid.onion/debian trixie main
deb  tor://5ajw6aqf3ep7sijnscdzw77t7xq4xjpsy335yb2wiwgouo7yfxtjlmid.onion/debian-security trixie-security main

Edit  /etc/apt/sources.list.d/mobian.list  as root

Code:
sudo nano /etc/apt/sources.list.d/mobian.list

and put    tor+  in front of  the https://repo.mobian.org/   url

Code:
tor+https://repo.mobian.org/

Run

Code:
sudo apt update
  Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  bookworm vs trixie discussion for mobian in pinephone regular. zetabeta 45 12,066 02-22-2025, 06:51 AM
Last Post: anonymous
  mobian phosh on screen keyboard not popping up for Chromium/Electron apps grump_fiddle_reinstall 1 293 01-15-2025, 08:08 PM
Last Post: Kevin Kofler
  How to use QR codes on Mobian Sid(unstable) Pinephone Pro biketool 1 310 01-02-2025, 12:47 PM
Last Post: zetabeta
  Upgrade to Mobian (Trixie) Staging biketool 13 1,587 12-29-2024, 10:35 AM
Last Post: biketool
  Mobian Bulleyes aberrio 0 335 12-16-2024, 08:27 AM
Last Post: aberrio
  Mobian, Suspend, and Audio Playback biketool 0 365 12-11-2024, 12:56 AM
Last Post: biketool
  atinout binaries for mobian/debian? NeutralGrey 4 1,957 10-31-2024, 04:16 AM
Last Post: astylethargic
  Mobian-Kicksecure? 3460p 0 1,152 05-26-2024, 02:09 PM
Last Post: 3460p
  Mobian repository status henrythemouse 16 13,541 04-10-2024, 10:02 AM
Last Post: diederik
  cant verify mobian image at website gnugpg penguins_rule 0 1,067 03-18-2024, 08:54 PM
Last Post: penguins_rule

Forum Jump:


Users browsing this thread: 1 Guest(s)