Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Stephen Kitt
On Thu, 9 Apr 2020 20:06:33 +0200, Markus Koschany wrote: > So when the quint essential message is, it is a matter of opinion and a > special form of verification is not mandated by Policy, then why don't > you work closer with the member of this team and help him to implement > the standard

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
Am 09.04.20 um 15:18 schrieb Stephen Kitt: > Le 09/04/2020 14:47, Markus Koschany a écrit : >> Am 09.04.20 um 13:58 schrieb Stephen Kitt: >>> Le 09/04/2020 13:44, Markus Koschany a écrit : Am 09.04.20 um 13:24 schrieb Stephen Kitt: > On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Stephen Kitt
Le 09/04/2020 14:47, Markus Koschany a écrit : Am 09.04.20 um 13:58 schrieb Stephen Kitt: Le 09/04/2020 13:44, Markus Koschany a écrit : Am 09.04.20 um 13:24 schrieb Stephen Kitt: On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany wrote: Am 09.04.20 um 11:36 schrieb Ivo De Decker: [...]

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Stephen Kitt
Le 09/04/2020 15:18, Stephen Kitt a écrit : [...] When a user installs a package in Debian, there’s a reasonable expectation that the user will get when the maintainer intended. Even Sorry, *what* the maintainer intended. [...]

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
Am 09.04.20 um 13:58 schrieb Stephen Kitt: > Le 09/04/2020 13:44, Markus Koschany a écrit : >> Am 09.04.20 um 13:24 schrieb Stephen Kitt: >>> On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany >>> wrote: Am 09.04.20 um 11:36 schrieb Ivo De Decker: > It seems runescape downloads a binary

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Stephen Kitt
Le 09/04/2020 13:44, Markus Koschany a écrit : Am 09.04.20 um 13:24 schrieb Stephen Kitt: On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany wrote: Am 09.04.20 um 11:36 schrieb Ivo De Decker: It seems runescape downloads a binary and runs it, without verifying its integrity. At least the

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
Am 09.04.20 um 13:24 schrieb Stephen Kitt: > On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany wrote: >> Am 09.04.20 um 11:36 schrieb Ivo De Decker: >>> It seems runescape downloads a binary and runs it, without verifying its >>> integrity. At least the download happens using https, but no

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Simon McVittie
On Thu, 09 Apr 2020 at 12:37:03 +0200, Markus Koschany wrote: > Am 09.04.20 um 11:36 schrieb Ivo De Decker: > > It seems runescape downloads a binary and runs it, without verifying its > > integrity. At least the download happens using https, but no other > > verification is done. > > Could you

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Stephen Kitt
On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany wrote: > Am 09.04.20 um 11:36 schrieb Ivo De Decker: > > It seems runescape downloads a binary and runs it, without verifying its > > integrity. At least the download happens using https, but no other > > verification is done. > > Could you

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
Control: tags -1 moreinfo Am 09.04.20 um 11:36 schrieb Ivo De Decker: > package: runescape > severity: serious > > Hi, > > It seems runescape downloads a binary and runs it, without verifying its > integrity. At least the download happens using https, but no other > verification is done. Could

Processed: Re: Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Debian Bug Tracking System
Processing control commands: > tags -1 moreinfo Bug #956276 [runescape] runescape: downloads unverified binary and runs it Added tag(s) moreinfo. -- 956276: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=956276 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Ivo De Decker
package: runescape severity: serious Hi, It seems runescape downloads a binary and runs it, without verifying its integrity. At least the download happens using https, but no other verification is done. Cheers, Ivo