Hacker News new | ask | show | jobs
by madeofpalk 3579 days ago
Except that time where the auto update mechanism was actually distributing a hacked version

http://www.macrumors.com/2016/03/07/transmission-malware-dow...

1 comments

No it did not. They distributed a new version via the build-in updater to try to remove the malware from the copies downloaded from the website. Sparkle use a digital signature and the malware author did not have the private key to create a valid signature for the update. So even if a malware was downloaded, Transmission would report a "invalid archive downloaded" error.