Conversation

This Tweet was deleted by the Tweet author. Learn more
Replying to
Well… to be fair, it’s more complicated than that. According to that thread, VLC apparently verifies downloaded updates using GPG, although rcombs then found a bug in that
2
This Tweet was deleted by the Tweet author. Learn more
Replying to and
If they had proper signature verification including prevention of downgrade attacks it wouldn't be needed for the baseline update security, but it's still useful. An attacker modifying the traffic could still do things like a disk space DoS by providing an infinite size file.
1
Replying to and
They could make it robust against that kind of disk space exhaustion too, but I still think it's a good idea to use HTTPS, ideally via system libraries that get updated automatically and aren't going to be adding any real attack surface since it's already heavily used / exposed.
1
Replying to and
One way to prevent downgrade attacks would be having signature verification of the metadata (the other being checking that the metadata inside the update matches), which would deal with that. It's easiest to start with HTTPS and then perfect all these things over time though.