The best argument is for defense-in-depth—in case someone breaks their signing scheme.
Edit: u/dcbadacd makes a great point about old but vulnerable versions potentially being served up by a MITM.
The best argument is for defense-in-depth—in case someone breaks their signing scheme.
Edit: u/dcbadacd makes a great point about old but vulnerable versions potentially being served up by a MITM.
Signing also doesn't stop serving old-and-vunerable-versions as the latest which is in my opinion a vunerability. Apt also has that vulnerability.
But the use of a weak signing scheme is just an argument in favor of switching to a better signing scheme. Though I guess it is also real world evidence in favor of defense-in-depth.
> if the update blob indicates a key other than the hardcoded one, it downloads the requested public key from the VLC update server over HTTP and does nothing further to verify the key itself. This means that all an attacker would have to do to serve a malicious update would be to sign it with their own key, then serve the matching public key when VLC requests it.
I think they should've included this in the original report, because if true then it really changes the severity.
Which makes the report totally valid, if true.