Re: Scripts that run insecurely-downloaded code
Davide Prina wrote:
These scripts are using wget or curl, which both say they do verify
certificates. If they do not do so correctly, please report this.
Not all the software that implement HTTPS verify the validity of the certificate and the validity of all the certification chain.
For example where I work has been invalidated a certificate, but for mistake the new valid one was not loaded on a https site. With Debian and Firefox I cannot access that site (I get "the certificate is not valid" or something similar), but other people, that use another OS, can access it with internet explorer and chrome, but not with Firefox.
Since this involved a revoked certificate, possibly