Security of MiKTeX package manager

Philipp <[email protected]> Fri, 28 Apr 2017 22:05:38 +0200
Newsgroups gmane.comp.tex.miktex
Message-ID <CAN8x386sf=KHkShQtyxZFc2VhVDSL7-hrWo6NHHjwzGXx3Heig@mail.gmail.com>
Hi all,

as someone who's a bit paranoid concerning my computers' security, I
was wondering how secure it is to install or update packages with
MiKTeX package manager.

>From what I have seen, packages are downloaded over http, not https.
Are digital signatures or something alike applied?
If not, the package download process seems vulnerable to
man-in-the-middle attacks. While this probably isn't much of an issue
for packages that contain fonts, styles or similar stuff, there are
also some packages that include DLLs or even executable programs
(e.g., BibTeX), which an attacker could replace with manipulated
versions.

I must admit that it is unlikely that someone would actually exploit
this (if it is possible), but I would feel better if it wasn't
possible at all ;-)

Regards,
Philipp

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Q: How can I leave the mailing list?
A: See http://docs.miktex.org/faq/support.html#leavingml