mirrored image from https://66.media.tumblr.com/a4e22db75a76bbe0f15452caf6152de9/tumblr_naj03mEeUL1tjflgfo1_1280.png without alt text, sorry
Figure 1. mirrored image from https://66.media.tumblr.com/a4e22db75a76bbe0f15452caf6152de9/tumblr_naj03mEeUL1tjflgfo1_1280.png without alt text, sorry.

Httpshaming:

Evernote checks for update over unencrypted HTTP, and the update packages are also downloaded over HTTP. But it’s signed code, right? What could go wrong?

It’s trivially easy to perform a man-in-the-middle attack to prevent future updates from ever being received, or to redirect the user to unsigned or malicious code, that may or may not run.

There is a DSA signature on the file at the update URL, and there’s signatures on the files and a certificate OU deep within the app contents… but that all assumes the user can get to the update, and download it securely.

Good news for persistent threats, bad news for the millions of Evernote users who want to get critical security updates.

This looks easy enough to fix.  

(Submitted by Phillip Knoll)

August 19th, 2014 8:38am

Proximate posts in the Tumblr collection
Newer nevver: Modern toss 22 August 2014
These bottles of ginger ale were the exact same size when fermentation started Sunday. on Flickr. 22 August 2014
This post httpshaming: Evernote checks for update over unencrypted HTTP, and the update packages are also downloaded over HTTP. But it’s signed code, right? What could go wrong? It’s trivially easy to perform a man-in-the-middle attack to prevent future updates from ever being received, or to redirect the user to unsigned or malicious code, that may or may not run. There is a DSA signature on the file at the update URL, and there’s signatures on the files and a certificate OU deep within the app contents… but that all assumes the user can get to the update, and download it securely. Good news for persistent threats, bad news for the millions of Evernote users who want to get critical security updates. This looks easy enough to fix.   (Submitted by Phillip Knoll) 19 August 2014
Older View my 2 latest photos on Flickr: https://flic.kr/u/2mJ1Jd/aHsk1m48N3 17 August 2014
~ brew install smoked porter on Flickr. 17 August 2014
Proximate posts in the General collection
Newer For the wall? 21 August 2014
Twitter post from August 20, 2014, 501920654803755009 20 August 2014
This post httpshaming: Evernote checks for update over unencrypted HTTP, and the update packages are also downloaded over HTTP. But it’s signed code, right? What could go wrong? It’s trivially easy to perform a man-in-the-middle attack to prevent future updates from ever being received, or to redirect the user to unsigned or malicious code, that may or may not run. There is a DSA signature on the file at the update URL, and there’s signatures on the files and a certificate OU deep within the app contents… but that all assumes the user can get to the update, and download it securely. Good news for persistent threats, bad news for the millions of Evernote users who want to get critical security updates. This looks easy enough to fix.   (Submitted by Phillip Knoll) 19 August 2014
Older Twitter post from August 18, 2014, 501506567653441538 18 August 2014
Twitter post from August 18, 2014, 501457061360574464 18 August 2014

Pizza Slow (high quality)

© 2026 gravely