You are not logged in.
This may be a bit of a stupid question, but how can one trust other official arch mirror servers? If it's related to cryptography-keys, where and how do I manage/validate/update the keys and the packages?
Offline
Partial answer: https://wiki.archlinux.org/title/Pacman/Package_signing
Offline
Trust them to do / not do what exactly?
I don't trust them. Trust is irrelevant if the packages are signed.
A malicious actor running a mirror could certainly slow down my updates, but this would soon be discovered and their mirror replaced by a better functioning one. But it'd be hard for a malicious mirror operator to actually do anything to harm or compromise my system - so I don't need to trust them.
"UNIX is simple and coherent" - Dennis Ritchie; "GNU's Not Unix" - Richard Stallman
Offline
I don't trust them. Trust is irrelevant if the packages are signed.
There are so many easy compromises with unsigned databases....
Offline
I'm not even sure we've understood the question. What is an official arch mirror server in this context?
Offline