In 2016, why do download.documentfoundation.org and all mirrors still use HTTP, not HTTPS?

asked 2016-07-06 21:53:59 +0100

Jacob C. gravatar image

For a significant site distributing software in this day and age, it's odd. Given that the pages themselves could be modified in transit, a PGP signature or the hashes listed on a mirror list page aren't on their own so reassuring, at least against concerns of intentional compromising of the downloaded file (as opposed to accidental corruption).

While documents like the mirror list and PGP signature canbe retrieved over HTTPS (although links on libreOffice.org and from the button in software''s own update check dialog lead to an HTTP page), the binary package download links are still all HTTP. Even if you edit the URL of the "Download file from preferred mirror" link to HTTPS, it doesn't help: You get a 302 redirect to an HTTP mirror. e.g. https://download.documentfoundation.o... sends me (via an HTTP 302 redirection) to http://noodle.portalus.net/tdf/libreo...

What gives? Offering only HTTP downloads is severely anachronistic, like something out of the era when downloading from SunSITE mirrors was common. In 2016, MitM attacks are a reality.

Currently, to be reasonably sure they're getting a legitimate file, a user has to go though an unnecessary number of hoops:

  1. Download the binary package.
  2. Go to the download mirror page.
  3. Click on the SHA-256 link.
  4. In the browser's address bar, manually change the URL to https://..., and hit Enter.
  5. Save that file (making sure the browser doesn't append an extension like ".txt", something like filename.sha256.txt)
  6. Run a check, e.g. on OS X, "shasum -a 256 -c LibreOffice_5.1.4_MacOS_x86-64.dmg.sha256"

Most users will not do that. The current arrangement therefore seems irresponsible to me. Is there some compelling reason I'm missing to not offer LibreOffice over HTTPS? If it's that the Document Foundation hasn't been able to get all the mirror providers on board to serve over HTTPS, why not at least get someof them to do so, and only redirect to those ones from any 302 redirection served by https://download.documentfoundation.o.... requests? (and on the mirror list pages, explicitly mark the others as insecure HTTP).

edit retag flag offensive close merge delete

Comments

tdelmas gravatar imagetdelmas ( 2016-07-09 15:51:06 +0100 )edit

Thanks, tdelmas.

m.a.riosv, I take it you're implying that this would be better posted there, as it's a website issue? Perhaps I should have posted it there, but it wasn't indicated at libreoffice.org/get-help/feedback/ that website questions/issues should be reported there, so I wound up here. Anyway, it's probably a moot point now that tdelmas has filed an actual bug report, so I don't think I'll cross-post it now. (Note: Continuing the trend, that forum doesn't support HTTPS either...)

Jacob C. gravatar imageJacob C. ( 2016-07-12 21:31:24 +0100 )edit