Pain point · Permissions & security · Blocks work
Upgrade packages downloaded over insecure HTTP
1 source thread · first seen 2014-10
Summary
The one-click updater fetches the update zip over HTTP, allowing a man-in-the-middle to inject code; HTTPS and signed releases are requested.
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“The one-click updater downloads the latest `.zip` version over from an `http://` URL, which is not secure”