pizza slow (high quality)
mirrored image from https://66.media.tumblr.com/a4e22db75a76bbe0f15452caf6152de9/tumblr_naj03mEeUL1tjflgfo1_1280.png without alt text, sorry
Figure 1. mirrored image from https://66.media.tumblr.com/a4e22db75a76bbe0f15452caf6152de9/tumblr_naj03mEeUL1tjflgfo1_1280.png without alt text, sorry.

Httpshaming:

Evernote checks for update over unencrypted HTTP, and the update packages are also downloaded over HTTP. But it’s signed code, right? What could go wrong?

It’s trivially easy to perform a man-in-the-middle attack to prevent future updates from ever being received, or to redirect the user to unsigned or malicious code, that may or may not run.

There is a DSA signature on the file at the update URL, and there’s signatures on the files and a certificate OU deep within the app contents… but that all assumes the user can get to the update, and download it securely.

Good news for persistent threats, bad news for the millions of Evernote users who want to get critical security updates.

This looks easy enough to fix.  

(Submitted by Phillip Knoll)

August 19th, 2014 8:38am

Proximate posts in the Tumblr collection
newer These bottles of ginger ale were the exact same size when fermentation started Sunday. on Flickr. 22 August 2014
this post httpshaming: Evernote checks for update over unencrypted HTTP, and the update packages are also downloaded over HTTP. But it’s signed code, right? What could go wrong? It’s trivially easy to perform a man-in-the-middle attack to prevent future updates from ever being received, or to redirect the user to unsigned or malicious code, that may or may not run. There is a DSA signature on the file at the update URL, and there’s signatures on the files and a certificate OU deep within the app contents… but that all assumes the user can get to the update, and download it securely. Good news for persistent threats, bad news for the millions of Evernote users who want to get critical security updates. This looks easy enough to fix.   (Submitted by Phillip Knoll) 19 August 2014
older View my 2 latest photos on Flickr: https://flic.kr/u/2mJ1Jd/aHsk1m48N3 17 August 2014
Proximate posts in the General collection
newer Twitter post from August 20, 2014, 501920654803755009 20 August 2014
this post httpshaming: Evernote checks for update over unencrypted HTTP, and the update packages are also downloaded over HTTP. But it’s signed code, right? What could go wrong? It’s trivially easy to perform a man-in-the-middle attack to prevent future updates from ever being received, or to redirect the user to unsigned or malicious code, that may or may not run. There is a DSA signature on the file at the update URL, and there’s signatures on the files and a certificate OU deep within the app contents… but that all assumes the user can get to the update, and download it securely. Good news for persistent threats, bad news for the millions of Evernote users who want to get critical security updates. This looks easy enough to fix.   (Submitted by Phillip Knoll) 19 August 2014
older Twitter post from August 18, 2014, 501506567653441538 18 August 2014