Hacker News new | ask | show | jobs
by jakobegger 3863 days ago
Hosting the downloads themselves via HTTPS is completely useless if the link to that file is transferred over HTTP.
1 comments

Link to the repo/releases page...
Jesus Christ, you really don't understand, do you?

If the original website is insecure, everything could be faked, including the link to the releases page.

If HN readers don't understand this, who does?