Topic: Update does not use SSL

Must I really explain the implications of this?

Downloading the FireGPG update via insecure HTTP allows the potential for malware to be injected into the update.  Now we have malware in our system with access to our public/private keyring, possibly monitoring when we enter our secret-key passcode and uploading this information to some server in China.  Fantastic!

That's one scenario.  So, please, make the update use HTTPS.

Re: Update does not use SSL

And Firefox 3 wants https. We haven't the choise smile

Re: Update does not use SSL

Ok, I do some cheks, and we dosen't need https for firefox3, but updates files will be signed (not the extention).

I will look if we can sign the xpi now smile