Hacker News new | ask | show | jobs
by asveikau 51 days ago
> 124 days to get AMD to add an s to a couple of HTTP URLs!

I disagree that they should only add HTTPS and call it done. They should also add some kind of signing check before running the payload.

If anything I'd say HTTPS is optional if they do that part.

2 comments

You'd imagine they'd just reuse and verify the Authenticode signature the very least.
They added CRC32 lol