logoalt Hacker News

pmontrayesterday at 12:12 PM1 replyview on HN

If somebody is MITMing a target person, they will respond positively to "update available?" calls from that person and then serve the tainted update. The article does not say what the frequency of auto update check is. Let's say one per day. If somebody is targeted it's one day away from RCE.


Replies

thedanbobyesterday at 12:41 PM

The update check is HTTPS, only the files themselves are HTTP.

show 2 replies