Conversation

This Tweet was deleted by the Tweet author. Learn more
Replying to
Well… to be fair, it’s more complicated than that. According to that thread, VLC apparently verifies downloaded updates using GPG, although rcombs then found a bug in that
2
This Tweet was deleted by the Tweet author. Learn more
Replying to and
If they had proper signature verification including prevention of downgrade attacks it wouldn't be needed for the baseline update security, but it's still useful. An attacker modifying the traffic could still do things like a disk space DoS by providing an infinite size file.
1
Replying to and
They could make it robust against that kind of disk space exhaustion too, but I still think it's a good idea to use HTTPS, ideally via system libraries that get updated automatically and aren't going to be adding any real attack surface since it's already heavily used / exposed.
1