{
  "$type": "site.standard.document",
  "bskyPostRef": {
    "cid": "bafyreiau2f7dfxw63nbfut7fzjxl6geldfrofne7b52ayhkq7loonfc5ai",
    "uri": "at://did:plc:haakkg7y3xdghcdmprxeexso/app.bsky.feed.post/3mn4pwp2hi7i2"
  },
  "path": "/t/linux-packages-mirrors/38247#post_2",
  "publishedAt": "2026-05-31T02:38:43.000Z",
  "site": "https://discuss.privacyguides.net",
  "textContent": "A good package manager will check for cryptographic signatures corresponding to downloaded packages, so that should keep you safe; even if someone intercepted and replaced the HTTP packets, as long as the official signatures themselves are fetched securely. It’d still be ideal to have the connections be over TLS, but it’s not strictly necessary for this use case. (It still doesn’t keep private **which** packages you’re installing, for example)",
  "title": "Linux packages mirrors"
}