Skip to content

Insecure downloads: cargo-leptos downloads binaries without checking their cryoptographic hashes #561

@yurivict

Description

@yurivict

For example this download.
src/ext/exe.rs also has a lot of other URLs that are used to download various binaries without checking cryptographic hashes.

An adversary can intercept internet connections and can substitute a binary with the malicious or compromised one.

Please note that almost all large corporations intercept https connections by forcing users to install their https certificates so that most users don't even know that they might be spied on. Some countries require everybody to install https certificates. Malicious actors might also run malicious WiFi access points and intercept https connections.

The situation when someone can be snooping on https connctions already takes place in a lot of situations.
This is why it's important to check cryptographic hashes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions