Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CoRD Insecure Update Mechanism #80

Closed
iallison opened this issue Jun 20, 2016 · 1 comment
Closed

CoRD Insecure Update Mechanism #80

iallison opened this issue Jun 20, 2016 · 1 comment

Comments

@iallison
Copy link

It appears that CoRD uses an insecure update mechanism.
In the CoRD /Applications/CoRD.app/Contents/Info.plist file the SUFeedURL is set to:
http://cord.sourceforge.net/sparkle.xml

This setting makes your application vulnerable to a Man-in-the-middle attack application updates.

Please update the SUFeedURL string to use https instead of http to mitigate this issue.

@peelman
Copy link
Collaborator

peelman commented Jul 25, 2016

CoRD is deprecated and we encourage the move to other clients:

https://github.com/dorianj/CoRD/blob/master/README.md

@peelman peelman closed this as completed Jul 25, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants