Page 1 of 1

Downloads over HTTPS instead of over HTTP

Posted: 07 Jul 2016 00:48
by r_spilker
Hi,

The Forum and Wiki are HTTPS, but the website and especially the download page are not.

http://get.videolan.org/vlc/2.2.4/win32 ... -win32.exe

I really don't like to download executables over HTTP because I don't know which man-in-the-middle has given it to me. Popular programs like VLC are an excellent target for these kind of attacks.

Is there someone here who is able to give an estimate on how difficult it is to change this and tell me who needs to be convinced it is a good idea?

Re: Downloads over HTTPS instead of over HTTP

Posted: 08 Jul 2016 10:07
by Jean-Baptiste Kempf

Re: Downloads over HTTPS instead of over HTTP

Posted: 22 Jul 2016 10:32
by r_spilker
Yes, that works. Then I suggest to update VLC to use HTTPS and then remove the HTTP download. What forum should I use to place these suggestions? Is VLC media player Feature Requests the correct one?

Re: Downloads over HTTPS instead of over HTTP

Posted: 23 Jul 2016 21:30
by Lotesdelere
I suggest to update VLC to use HTTPS and then remove the HTTP download. What forum should I use to place these suggestions? Is VLC media player Feature Requests the correct one?
For this particular point about the website you are already using the correct forum.

Re: Downloads over HTTPS instead of over HTTP

Posted: 25 Jul 2016 11:35
by Jean-Baptiste Kempf
Yes, that works. Then I suggest to update VLC to use HTTPS and then remove the HTTP download. What forum should I use to place these suggestions? Is VLC media player Feature Requests the correct one?
This will not happen. We have 100+ mirrors that we don't control, and they can't have HTTPS, and notably not with our HTTPS certificate.