4 ms·
All someone needs to do is hack the AMO servers and change out the XPI -- and no one would no the difference, because the packages aren't signed. Not to also m
by blcknight 12y ago
All someone needs to do is hack the AMO servers and change out the XPI -- and no one would no the difference, because the packages aren't signed.
Not to also mention, MITM attacks on the actual SSL connection.
Serving over HTTPS isn't a valid package signing strategy.
- bzbarsky 12y ago> Not to also mention, MITM attacks on the actual SSL > connection. The AMO cert is pinned in Firefox. If you MITM the connection, Firefox will refuse to connect to it.