danielvijge / SqueezeCloud

SoundCloud plugin for Squeezebox
GNU General Public License v2.0
26 stars 11 forks source link

More HTTPS #32

Closed mavit closed 3 years ago

mavit commented 3 years ago

Working SSL is required for the plugin, and many of these links already redirect to HTTPS anyway.

danielvijge commented 3 years ago

Is there any advantage of downloading over HTTPS from the point of LMS?

mavit commented 3 years ago

If we download plugins over HTTP, a man in the middle can have us execute arbitrary code.

To put it another way, is there an advantage of downloading over HTTP nowadays?

mavit commented 3 years ago

If we download plugins over HTTP, a man in the middle can have us execute arbitrary code.

On second thoughts the SHA1 checksum probably mostly covers us for now, although I understand that SHA1 is looking pretty shaky these days.