• Show log

    Commit

  • Hash : 3562e384
    Author : Paul Eggert
    Date : 2017-09-16T13:03:36

    Prefer https: URLs
    
    In Gnulib, Emacs, etc. we are changing ftp: and http: URLs to use
    https:, to discourage man-in-the-middle attacks when downloading
    software. The attached patch propagates these changes upstream to
    Automake.  This patch does not affect files that Automake is
    downstream of, which I'll patch separately.
    
    Althouth the resources are not secret, plain HTTP is vulnerable to
    malicious routers that tamper with responses from GNU servers,
    and this sort of thing is all too common when people in some other
    countries browse US-based websites. See, for example:
    
    Aceto G, Botta A, Pescapé A, Awan MF, Ahmad T, Qaisar
    S. Analyzing internet censorship in Pakistan. RTSI
    2016. https://dx.doi.org/10.1109/RTSI.2016.7740626
    
    HTTPS is not a complete solution here, but it can be a significant
    help. The GNU project regularly serves up code to users, so we should
    take some care here.