Closed Bug 1410747 Opened 7 years ago Closed 7 years ago

Firefox installer is downloading browser via http (not https)

Categories

(Firefox :: Untriaged, defect)

58 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 1410458

People

(Reporter: giomac, Unassigned)

Details

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.102 Safari/537.36 Vivaldi/1.93.955.38

Steps to reproduce:

Downloaded and run firefox installer for windows from getfirefox.com


Actual results:

see following url in transparent proxy, which means download goes through http
1508705230.582  36999 172.28.30.21 TCP_MISS/200 38701542 GET http://download.cdn.mozilla.net/pub/firefox/releases/56.0.1/win64/en-US/Firefox%20Setup%2056.0.1.exe - ORIGINAL_DST/92.51.99.200 application/x-ms


Expected results:

download should go through https, not sure if installer is checking integrity and/or signing key of package (if exists), if not - this is a serious issue.
Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 7 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.