No, you're confusing two vectors of attack. I'm saying that if you fan trust the vendor, then you're still at risk from downloading malicious software that was manipulated between the vendor and you (man in the middle attack), unless you verified a signature using a key stores offline (note https is still vulnerable because the keys are stored online)
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: