Skip to content

use Valid-Until field to prevent downgrade attacks for deb.torproject.org

To prevent downgrade and stale mirror attacks against deb.torproject.org, please use the Valid-Until field.

Since you are using reprepro, you can add in your conf/distributions file

ValidFor: 2w

(Or ValidFor: 4w or 1m.) under every instance of "Label:" or so.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information