So has anyone figured out how the Transmission binary was built and uploaded? Good to know the effects, but the cause is more important…
@chockenberry and I guess technically Gatekeeper can't detect changed developer when you replace the .app, but I think Sparkle does that
-
-
.
@kuba_suder Yeah, that’s why I think an in-depth analysis of the attack is important. Something critical changed and no one noticed. -
@chockenberry@kuba_suder wasn’t it the Sparkle updater vulnerability? That’s what I assumed - View other replies
-
@aarond@chockenberry if it indeed only affected new downloads (can't find that now) then it's completely unrelated to Sparkle -
@aarond@chockenberry one user on Transmission's forum wrote: "my update in Transmission failed due to a wrong signature" -
@aarond@chockenberry so I think Sparkle stopped it, but if you went to the site and downloaded it manually, then you got the bad version -
@kuba_suder@aarond Probably because they didn’t have the Sparkle private key to create the DSA signature. We’re back to the build :-)
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Count Franken
Kuba Suder
Aaron Dunlap