Coder Social home page Coder Social logo

Comments (7)

vslavik avatar vslavik commented on August 23, 2024

I'm leaning towards verifying Authenticode signatures instead (or in addition to DSA). Sparkle is moving in that direction already, so it seems a bit pointless to adopt a to-be-obsoleted scheme now:

sparkle-project/Sparkle#48
sparkle-project/Sparkle@21f9546

from winsparkle.

dwchung-zz avatar dwchung-zz commented on August 23, 2024

Do you have a timeline of when you'll be supporting verifying Authenticode signatures?

from winsparkle.

vslavik avatar vslavik commented on August 23, 2024

No, I don’t (seriously? In OSS?). One thing that would definitely speed things up, though, would be contributions...

from winsparkle.

zsszatmari avatar zsszatmari commented on August 23, 2024

Slightly related question: Does WinSparkle support downloading the xml from https:// but only if ssl cert is okay?
I couldn't find any mention about this about the doc, but either executable signature checking or https xml fetching seems to be a minimum for not opening a backdoor on user's machine.
Thank You for the quick answer, and the awesome work so far!

from winsparkle.

vslavik avatar vslavik commented on August 23, 2024

related

That word doesn’t mean what you think it means. Please don’t post completely off-topic comments like this.

Does WinSparkle support downloading the xml from https:// but only if ssl cert is okay?

You have the code at your disposal, why don’t you verify it yourself and if there’s any issue, submit a patch?

for the quick answer

This is a volunteer, community project, please don’t treat it as a commercial offering with support. Instead, contribute — even if it’s “only” information or documentation improvements.

from winsparkle.

zsszatmari avatar zsszatmari commented on August 23, 2024

I think it's not off topic at all. The same people who think they need DSA signed updates might just be satisfied with https based xml download.
Anyway, looking into the code, it uses InternetOpenUrl(), which is not very well documented in this regard, but trying it out (see http://stackoverflow.com/questions/29545544/is-internetopenurl-function-on-windows-secure-enough-if-not-how-to-make-it-str/29576201#29576201), it seems that it indeed checks https validity by default. So the answer to my own question is yes.

from winsparkle.

vslavik avatar vslavik commented on August 23, 2024

I think it's not off topic at all.

This issue is for tracking support for DSA signatures. You ask a question about validation of certificates, which is something that has zero overlap with the issue’s subject, technically or thematically. You are off topic by definition. By your the-same-people logic, anything about WinSparkle would be on-topic in any issue...

from winsparkle.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.