4 ms·
Yep, they're still rather vulnerable. I guess their approach would stop a dumb MitM which just replaces any .exe download. It also protects against the downlo
by croikle 13y ago
Yep, they're still rather vulnerable. I guess their approach would stop a dumb MitM which just replaces any .exe download. It also protects against the download server being compromised, assuming the original server is fine and your connection is clean.
The best way is to check the signature, but that requires GPG in the first place (and trust on the key remains hairy). At least they could serve the site with HTTPS (GPGTools does this right).