After the Sparkle security vulnerability found and the malware delivered via Transmission, how the heck can I trust any downloads anymore?
@simX It's weird that Sparkle devs had the foresight to verify signatures but intentionally disabled WebView security features.
-
-
@rosyna How do you mean? Isn’t JavaScript on by default? -
@mjtsai It's that navigation policy thing I mentioned before. Sparkle devs made it pass all URLs to LaunchServices, which is not a default. - View other replies
-
@mjtsai This discussion specificallyhttps://twitter.com/rosyna/status/694728041407205377 …
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Simone Manganelli
Rosyna Keller
Michael Tsai