Hacker News new | ask | show | jobs
by palant 1265 days ago
Disclaimer: I’m the author of this article.

Did you notice the plain HTTP (no SSL) download URLs for the “security software”? If not, you are missing out!

1 comments

I didn't! The download URLs on that page all seemed to be HTTPS for me, though my browser might be forcing the HTTPS connection or something. Or it's just the macOS versions. I'd 100% believe there's plain HTTP requests in there somewhere. I was trying to get the JS to serve me the software for other OSes but was struggling since it seems to do more than just a User-Agent check. Fortunately that JS is the totally unobfuscated kind.

btw, love your article! Such an interesting obscure little corner of the world of technology. Hope to read more.