View Single Post
Posts: 71 | Thanked: 36 times | Joined on Nov 2009 @ CT, USA
#20
Originally Posted by slaapliedje View Post
Debian supports GPG signed packages as well, at least in Lenny+. Unfortunately most of Maemo 5 is built off of Debian Etch, so no GPG signing to be seen. This could easily be added though, so I don't know why it isn't.
Package signing goes back much further than that--it was present in Potato and probably before that. Many (most?) "nonofficial" official repositories use gpg signing also, like Debian Multimedia, but this doesn't prevent anyone from downloading unsigned .debs and installing packages that way.

The n900 comes with a trusted keys keyring although I'm not sure what it's used for. Regardless, it's a matter of Nokia using security tools already available in .deb and .rpm package management, and not a package format problem.