|
|
|
|
|
by geofft
4228 days ago
|
|
Even signed automatic security updates, where the vendor runs the update server, still allow the vendor to inject targeted attacks in your binary. There are ways to mitigate this, but not well given the design constraints of closed-source software. |
|
If you meant that a man in the middle can do that, then if things are implemented correctly on the app's end and if an attacker doesn't have vendor's private key, then - no, of course, they cannot inject anything that way.