4 ms·
If you are so concerned about downloading anything via HTTP, why not always use a VPN? At least that way you aren't susceptible to local MITM. Just make sure yo
by chill1 13y ago
If you are so concerned about downloading anything via HTTP, why not always use a VPN? At least that way you aren't susceptible to local MITM. Just make sure you trust your VPN :)
Edit: Oh, plus you can always use a checksum to verify your download packages [1] :)
[1] http://nodejs.org/dist/v0.10.26/SHASUMS.txt http://nodejs.org/dist/v0.10.26/SHASUMS.txt
- handsomeransoms 13y ago> why not always use a VPN? Because then you're susceptible to remote MITM? VPNs are useful but do not replace end-to-end encryption.
- CSDude 13y agoYou know this links is also not served on HTTPS. So local MITM can change the checksum on this page too.
- IgorPartola 13y agoWhat others said. Checksums downloaded via HTTP are just as easy to spoof as the tarball. The VPN protects you part of the way but not the entire way. Now, if you said that I could verify the download because it was signed using the publisher's GPG key and that key was widely trusted, then I might have entertained the idea. Then again, that is very non-standard compared to getting a $10 TLS cert.