Erlenmayr (erlenmayr) wrote :

There would be a much lower risk if HTTP (without TLS) were not still the default for repositories.

This can actually also be abused by a MitM, he can always make your APT think that there are no new updates (a simple 304 Not Modified works), and then exploit recent vulnerabilities of which you have not received the fix.