How is an update supposed to work if the connection to the timestamp is prevented/intercepted? How if the connection to the repository is prevented/intercepted? Using a single connection leads to less potential failure modes.
How is an update supposed to work if the connection to the timestamp is prevented/intercepted? How if the connection to the repository is prevented/intercepted? Using a single connection leads to less potential failure modes.
I think that TUF and an https based system would both warn if an adversary or adverse conditions was blocking connectivity to the "root file". I don't think either can do anything more than warn. TUF makes it easier to mirror the root file (because it doesn't require HTTPS), so TUF has the advantage there. But I think an attacker could probably as easily (more easily?) block or intercept every TUF mirror (over HTTP) as they could block a small number of HTTPS update servers, so I'm not sure this is a huge advantage in real life.
I believe the same problems apply to delivery of the root file as to subsequent files; if you are concerned about malicious attackers interfering with file delivery it seems you should prefer HTTPS. Both TUF and HTTPS-for-root are basically agnostic to the delivery mechanism for subsequent files, I believe, so I don't see this as an advantage for either: for both an attacker can trivially block individual files over HTTP; if you use HTTPS as the transport it is still trivial to block connectivity altogether, and neither approach offers a solution to this no-connectivity attack.