Hacker News new | past | comments | ask | show | jobs | submit login

Yes, I made a mistake about the key. Adding a key is safe by itself. However by adding third-party repository you are granting Signal a permission to replace packages on your system (unless you manually whitelist package names in apt preferences), and by installing a package from Signal repository you grant it root access to your system.

Sadly debian-based distributions do not respect the principle of least privileges and grant unnecessary permissions to installation scripts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: