Security of MiKTeX package manager
Philipp <[email protected]> Fri, 28 Apr 2017 22:05:38 +0200
| Newsgroups | gmane.comp.tex.miktex |
|---|---|
| Message-ID | <CAN8x386sf=KHkShQtyxZFc2VhVDSL7-hrWo6NHHjwzGXx3Heig@mail.gmail.com> |
Hi all, as someone who's a bit paranoid concerning my computers' security, I was wondering how secure it is to install or update packages with MiKTeX package manager. >From what I have seen, packages are downloaded over http, not https. Are digital signatures or something alike applied? If not, the package download process seems vulnerable to man-in-the-middle attacks. While this probably isn't much of an issue for packages that contain fonts, styles or similar stuff, there are also some packages that include DLLs or even executable programs (e.g., BibTeX), which an attacker could replace with manipulated versions. I must admit that it is unlikely that someone would actually exploit this (if it is possible), but I would feel better if it wasn't possible at all ;-) Regards, Philipp ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Q: How can I leave the mailing list? A: See http://docs.miktex.org/faq/support.html#leavingml