Skip to content

Use https for update checks and verify hash of downloaded executable #4716

@nvaccessAuto

Description

@nvaccessAuto

Reported by jteh on 2014-12-20 01:23
Now that Python 2.7.9 verifies https certificates, we should move to using https for update checks. This will prevent MITM attacks for update checks. We should also include a hash for the executable in the update check response and verify it once downloaded to prevent MITM attacks for the download itself.

This requires changes in both NVDA and the server.
Blocked by #4715
Blocking #4803

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions