Well, regardless of exploitability, this attitude just destroyed any confidence I had in VLC's updater being secure. Seriously, WTF. https://trac.videolan.org/vlc/ticket/21737 …
Replying to @3RIKGH3NT
All my machines update over SSH from packages I build on my own package server which updates weekly over git-over-HTTPS from upstream with a restricted whitelist of CAs allowed.
0 replies
1 retweet
4 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.