Information
APT supports both HTTP and HTTPS transport for repository access. While official repositories for the target distributions use HTTPS by default, custom or third-party repositories added by administrators may be configured with HTTP. Repositories served over plain HTTP are susceptible to network interception - an attacker positioned between the system and a mirror could suppress specific security updates, withholding patches to keep the system vulnerable to known exploits, or intercept repository metadata to profile installed software versions.
APT verifies package integrity via GPG signatures, but plain HTTP transport leaves repository metadata and package lists exposed to network interception. An attacker positioned between the system and a repository mirror could suppress specific security updates, preventing patches from being applied and keeping the system vulnerable to known exploits. Enforcing HTTPS transport ensures the integrity and confidentiality of the repository communication channel, complementing GPG signature verification.
Solution
Edit each file in /etc/apt/sources.list.d/ that contains HTTP repository URIs and replace http:// with https://.
Example - legacy .list format:
deb https://deb.debian.org/debian bookworm main
Example - deb822 .sources format:
URIs: https://deb.debian.org/debian
Impact:
Changing a repository from HTTP to HTTPS requires that the repository server supports HTTPS. For local mirrors that serve only HTTP, switching the client to HTTPS without a corresponding server-side change will cause apt update to fail for that repository.