On Mon, 2014-06-23 at 16:19 +0000, Bart Martens wrote: 
> OK, your answer confirms that I wasn't overlooking anything. I'll also briefly
> answer your questions :
Well as said... I think the problem that people don't notice updates
unless they run the installer again, is also some severe problem...
Or do I miss anything here?


> > How?
> 
> For example I'm already using SHA512.
Uhm.... I'm a bit confused now... ^^

I've seen your message #66 and had a short glance at the code... but
it's a bit hard to read since there are so many files downloaded where I
don't quite understand why...

- where are you using SHA512?
- and how did you solve the issue with downgrade attacks now
- and how the one with blocking attacks? (i.e. when an attacker blocks
contact to the server with your files...  does the plugin tell the user
some appropriate error?

Cheers,
Chris.

Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to