What about: the same people do the automatic unattended autoupdate that you downloaded the original program from, or not?
What about: the same people do the automatic unattended autoupdate that you downloaded the original program from, or not?
Think at scale of years, and think of e.g. Microsoft of Adobe when pondering this question.
That said, you really shouldn't be running outdated torrent clients, like any network-connected programs. Case in point - the topic of this thread.
But also, SSL certificates don't certify the people you are connecting to but instead certify control over a domain which can change hands for various reasons.
If I download source and build and run it, and it downloads binaries from Microsoft and runs those, that isn’t remotely “the same people”.
Autoupdate is not good, especially with malicous actors between the user and the developer, which you can't really eliminate. Still it is not literally the same as a trojan.