QOwnNotes icon indicating copy to clipboard operation
QOwnNotes copied to clipboard

webpage: installation: debian: Insecure apt key install method

Open LeSpocky opened this issue 2 years ago • 3 comments

Expected behaviour

Provide secure installation instructions, see https://michael-prokop.at/blog/2021/02/16/how-to-properly-use-3rd-party-debian-repository-signing-keys-with-apt/ for example and reasoning.

Actual behaviour

Insecure installation instructions are provided. Main problem is: The documentation advises to download an arbitrary file and pipe it without further inspection into a process with root priviledges (adding the key or whatever is downloaded into the global apt trust store of the machine.

Steps to reproduce

Read https://www.qownnotes.org/installation/debian.html

Output from the debug section in the settings dialog

Expand **does not apply**

Relevant log output in the Log panel

Expand **does not apply**

LeSpocky avatar Oct 19 '21 09:10 LeSpocky

That were the instructions offered by OBS to use their repository. 😁 Feel free to create a pull requests for https://github.com/pbek/QOwnNotes/blob/develop/webpage/src/installation/debian.md.

pbek avatar Oct 19 '21 09:10 pbek

That were the instructions offered by OBS to use their repository. grin

Could not find it at https://openbuildservice.org/help/manuals/obs-user-guide/ … I would tell them otherwise. 😁

Feel free to create a pull requests for https://github.com/pbek/QOwnNotes/blob/develop/webpage/src/installation/debian.md.

Consider this ticket a reminder to myself. 😉

LeSpocky avatar Oct 19 '21 10:10 LeSpocky

Could not find it at https://openbuildservice.org/help/manuals/obs-user-guide/ … I would tell them otherwise. grin

It was printed on the build page of each repository. Can't find it anywhere on the new interface...

Consider this ticket a reminder to myself. wink

Great 😉

pbek avatar Oct 19 '21 12:10 pbek