Re: Request to Use HTTPS for Improved Security on Midnight Commander FTP.

"Yury V. Zaytsev via mc-devel" <mc-devel-+hD5IHI5XseWCegYutOAJTiNl0CLU6MPYPYVAmT7z5s@public.gmane.org> Sat, 17 Aug 2024 07:44:49 +0200
Newsgroups gmane.comp.gnome.apps.mc.devel
Message-ID <[email protected]>
Hi Kirill,

Unfortunately this is not something we can control.

We use the OSU OSL mirroring system and it still doesn't support HTTPS for custom mirror domains. In fact, you can access it with HTTPS, but the server will present a certificate for the wrong domain name (*.osuosl.org):

https://ftp.midnight-commander.org <https://ftp.midnight-commander.org/>

I don't know if this is better for Debian. Alternatively, you can use the shared mirror tree, but there is no guarantee that the name will not change in the future, which is why projects usually have their own subdomains:

https://ftp.osuosl.org/pub/midnightcommander/

I asked them half a decade ago what their plans were, and they said they'd like to fix this eventually, but right now they have other priorities. I asked again this summer (RT ticket #33475) and the answer was pretty much the same.

Maybe you can help get this fixed on their end. No idea if they are able to accept contributions to their infrastructure...

All the best,
Yury

> On 16. Aug 2024, at 23:22, Kirill Rekhov via mc-devel <mc-devel-+hD5IHI5XseWCegYutOAJTiNl0CLU6MPYPYVAmT7z5s@public.gmane.org> wrote:
> 
> Hello, are there any administrators of http://ftp.midnight-commander.org/ here? I was looking at the
> output of the `lintian` utility of the `mc` package in Debian, and I noticed the following:
> 
> -> debian-watch-uses-insecure-uri [debian/watch]
> 
> The `debian/watch` file of the `mc-4.8.31` package looks like this:
> version=3
> http://ftp.midnight-commander.org/mc-([\d\.]+)\.tar\.xz
> 
> An insecure connection (HTTP) is used, no HTTPS. I want to point out:
> 
> 1. HTTPS ensures that the data has not been modified in transit. This is especially important for
> packets, to ensure that they have not been tampered with or modified.
> 
> 2. HTTPS ensures that you are connecting to the real server, and not some fake site. This helps
> prevent man-in-the-middle (MITM) attacks.
> 
> 3. Although the packages may be publicly available, using HTTPS prevents monitoring and tracking of
> exactly which packages you download. This protects your privacy.
> 
> Could you use HTTPS? It's more secure.
> 
> ---
> Kirill Rekhov
> -- 
> mc-devel mailing list
> mc-devel-+hD5IHI5XseWCegYutOAJTiNl0CLU6MPYPYVAmT7z5s@public.gmane.org
> https://lists.midnight-commander.org/mailman/listinfo/mc-devel

-- 
mc-devel mailing list
mc-devel-+hD5IHI5XseWCegYutOAJTiNl0CLU6MPYPYVAmT7z5s@public.gmane.org
https://lists.midnight-commander.org/mailman/listinfo/mc-devel