Linked by Thom Holwerda on Fri 14th Sep 2007 14:02 UTC, submitted by tux68
Thread beginning with comment 271535
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
So each and every time you update, you go ahead and verify the server you are getting your updates from hasn't been compromised and is who it says it is? Somehow, I doubt that, and I can guarantee you most people wouldn't. Most people would just blindly enter their credentials and let the fake server do it's thing.
Please please please, I'll ask one more time, think before you post.






Member since:
2007-02-17
... but not such a weakness for update notifiers which still require manual input of credentials by a local user before any update is installed.
Also not such a weakness for any system where the binary executable payloads that are supposed to be coming from repositories are independently verifiable as authentic (by compilation of source).
Edited 2007-09-15 14:12