|
|
|
|
|
by huhtenberg
4228 days ago
|
|
Something to keep BT on its edge, but this is hardly a "security analysis" in an established conventional sense. It's a semi-random collection of surface observations from half-a-day of poking around. Sure, some of these may be indicative of serious underlying issues, but they may also be not. E.g. - > [MEDIUM] Attack vector potentiel : mise à jour automatique (silent update) du client en HTTP sur http://update.utorrent.com If they check the digital signature on an update package, this is not an issue. If they don't, it is. |
|
There are ways to mitigate this, but not well given the design constraints of closed-source software.