Friction

Pain point · Permissions & security · Blocks work

Upgrade packages downloaded over insecure HTTP

1 source thread · first seen 2014-10

Summary

The one-click updater fetches the update zip over HTTP, allowing a man-in-the-middle to inject code; HTTPS and signed releases are requested.

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“The one-click updater downloads the latest `.zip` version over from an `http://` URL, which is not secure”

Report this item