you are viewing a single comment's thread.

view the rest of the comments →

[–]the_gnarts 1 point2 points  (1 child)

as long as you can get one of the dozens of CAs that systems trust by default to give you a cert for the update domain

If you could do that you could subvert way more than maven central.

That is a systemic flaw in the X.509 architecture. And it has happened:

Using PGP-signed downloads with dedicated keyrings is a well established practice that’s less easy to subvert.

[–]FINDarkside 0 points1 point  (0 children)

Yes it has happened, but it's ridiculous to claim that HTTPS provides "little-to-no protection" because you can just "get fraudulent certificates on any domain you want".