4 ms·
This is almost what he said they block in the installer (downgrade attacks or replay attacks). The difference is there might still be an attack where: - User
by catwell 8y ago
This is almost what he said they block in the installer (downgrade attacks or replay attacks).
The difference is there might still be an attack where:
- User is at version N
- Version N + x is vulnerable
- Version N + x + y is latest
- User terminal asks for N + x + y and the attacker serves N + x
However this attack is much less critical than anything letting an attacker downgrade (only applies against versions updated infrequently).
Regarding VLC on Mac, which uses Sparkle, this issue could be avoided by using HTTPS just for the updates feed (AppCast), which is not mirrored.
- jbk 8y agoThis attack-to-not-latest exists, but it's very rare, since 99% of the security issue we have are in all versions of VLC, because of old code (2000s) in VLC and libavcodec. It could happen, sure, but that is very far from the "OMG, updates are in HTTP" issue, or even a downgrade attack.