End result for this issue is the same. Also, a comment is not the same as posting a bug.
End result for this issue is the same. Also, a comment is not the same as posting a bug.
In fact, if the HTTPS change is faster, this should be prioritized, given that the other issue might take a lot of time to fix: the old validation mechanism will have to be supported for a long time to keep older clients backwards compatible...
I'd take that the VLC guy had a bad day, otherwise that'd be a terrible reaction from someone involved in computer security.
We have no knowledge of "technical debt" or technical issues migrating from http to https. Videolan has 5 applications, perhaps all of them use the same update mechanism, which would broathen the scope of the fix.
What seems trivial (i agree), isn't always that in the software world. We need business knowledge of the VLC source or architecture for having a clear decision.
For what it's worth. I'll give the VLC developers the benefit of the doubt.
VideoLAN isn't in a position to enforce it's hosts to serve the files over TLS.
However the cryptography of the signature check will be updated in the future.
All the installs in a professional network where the use of a proxy changes the certificate would have trouble updating. So now it is changing changing http to https and be able to recover the company certificates in some way, in many different environments.
So yeah, the change is not trivial and will likely break the setup of millions of users. Downloading over http with a proper signature mechanism can be safe and is much easier for the users. If people have concerns over the way VLC is doing it, they are free to show how this can be broken and offer a fix.
Presumably those "professional networks" also use other software that already updates over HTTPS, this is not really VideoLAN's problem in 2019 when we are moving towards HTTPS everywhere.