On Sun, 31 Oct 2010 13:09:27 BST, Mario Vilas said:
Just signing the update packages prevents this attack, so it's not that hard
to fix.
Except if a signing key gets compromised, as happened to one Linux vendor
recently, causing a lot of kerfluffle...