Just give you an example: Many Germans think that http://www.7-zip.de/ is the official site and you still download 16.04 there.
Just give you an example: Many Germans think that http://www.7-zip.de/ is the official site and you still download 16.04 there.
The left side has a navigation to different translations of the page. All but the English version link to the German page as well.
I'm guessing it was once part of the build pipeline but has since been abandoned.
So yeah, it is an official source. It's just outdated
Unfortunately, 7-zip barely has any security involved. No digital signatures, no ASLR, no NX bit, no stack canaries, no nothing.
Hopefully these security concerns wake up Ivor. Its not the 90s anymore: developers have to participate to get a proper security posture. That's why Windows tried so hard to get everyone to use sandboxed Win10 Apps / Metro Sandbox by default, because these problems require the developers to care about security.
`whois 7-zip.de` resolves to a private person in Germany. This does not look official to me. More like a crowdsourced effort of providing translated websites with a dangerous effect in case of security vulnerabilities.
The versions provided are (as of 2018-05-04T10:20:00Z): en 18.05, de 16.04, zh 16.04/18.05, eo 18.01, fr 18.01, ja 18.05, pt 18.01, es 18.01, th 18.05, vi 18.01
I could also argue that automatic updates are themselves a security hole. They are a way for new code to be downloaded and run, without notifying the user. As a result, it means that your security depends on the security of a machine not under your control. Not too much of a risk for Firefox, but imagine having a program that auto-updated from SourceForge during its experimental fling as a malware distributor.
If you want the typical user on Windows to run updated software, your software has to at least entice updating if not auto-update straight away.
Not solving this whole distribution mess is by far the worst downside of Windows as a platform. Not getting malware when installing software on your Windows PC is hard.
(IIRC the maintainers learned the right lesson from that, and started signing their updates so it can't happen again)
If a project already performs telemetry, or if they have developer announcements, then the project has already increased its scope, and checking for updates is a relatively minor addition. If it is a well-behaved stand-alone application that doesn't make unwarranted external connections, then checking for updates is a large increase of scope.
Chocolatey is similar in some ways, but scoop works hard to isolate installed apps from each others, and from other users (which can be good and bad). It's a little like an apt-like wrapper for binary-only (x)stow.
[1] scoop is hosted on github - the download url is on proper ssl, the bare scoop.sh domain presents a github-cert.
Updates should be handled by the OS anyway IMO