signing certificate for tools from marketplace [message #1864491] |
Tue, 19 March 2024 17:00  |
Eclipse User |
|
|
|
I just downloaded and installed Eclipse IDE for Ent Java and Web.
Click on Help, then Marketplace. Search for android. The second result from the top. Install Android Development Tools.
Then I'm being asked to trust a cert without a cn and the signing algo md2withRSA. Who here is trusting md2?
See screenshot.
Now, if I try the same in Eclipse 2023-06, the cert is different. From Let's Encrypt. But also it displays that update authority is ieclipse.cn - Chinese tld domain...
Is this ieclipse.cn trustworthy source or no so?...
|
|
|
|
|
|
|
|
Re: signing certificate for tools from marketplace [message #1864525 is a reply to message #1864524] |
Thu, 21 March 2024 10:55   |
Eclipse User |
|
|
|
Ed,
thanks for responding.
I{m attaching 4 screenshots.
The first one shows that I have 2 different versions of Eclipse installed.
I did try installing this adt thing using both versions of Eclipse.
So, on second screenshot I {m in 2023'06 version of Eclipse.
I clicked Help and then Marketplace. etc.
If repeat these steps for the Eclipse 2024 (see the first screenshot), then I get a binary signed with md2/rsa. with md2/rsa a binary may be laced with crap.
Okay, there are many case studies that illustrate the risks.
I'll remind you just 2:
1. abandoned project Trader_X was modified by the koreans and redistributed.... later supply chain side attacks were staged - google for 3CX attack
2. https://qwiet.ai/a-rising-threat-malicious-python-packages/
I'm totally new to Eclipse repos. But looks like a cleanup effort maybe in order.
Also, my experience installing adt illustrates the lack of consistency in how extensions/repos are handled.
Attachment: ecl1.png
(Size: 772.73KB, Downloaded 381 times)
Attachment: ecl2.png
(Size: 104.65KB, Downloaded 101 times)
Attachment: ecl3.png
(Size: 92.56KB, Downloaded 112 times)
Attachment: ecl4.png
(Size: 130.75KB, Downloaded 114 times)
|
|
|
|
|
Re: signing certificate for tools from marketplace [message #1864535 is a reply to message #1864531] |
Fri, 22 March 2024 00:16   |
Eclipse User |
|
|
|
Clearly you feel insulted, which was not the intent, and you feel compelled to share that feeling with sarcasm and personal attacks, which is not so appropriate.
The point is that I tried installing the following and I get the host prompt dialog you showed using both 2023-06 and on 2024-03:
https://marketplace.eclipse.org/content/android-adt-extensions
But I do not get the prompt about artifact certificates for that listing in either installation.
On the other hand, I do get that artifact trust dialog you show using this listing, but that content comes from a different host:
https://marketplace.eclipse.org/content/andmore-development-tools-android%E2%84%A2
So given you didn't tell me exactly which thing you installed, I needed to make assumptions. Then, given I could reproduce what you showed using these two different listings, it seemed a safe assumption.
In any case, I think I'm done spending time helping you because I can better spend my time where its effective appreciated.
|
|
|
Re: signing certificate for tools from marketplace [message #1864550 is a reply to message #1864535] |
Fri, 22 March 2024 09:20  |
Eclipse User |
|
|
|
in the very first message I did say what exactly I tried installing.
1. Eclipse marketplace
2. the word "android" in the search box
3. with both versions of Eclipse search yields the same top results.
4. I did not try to install the very first result
5. as I mentioned in my very first message, it was always the second.
Now ADT is no longer supported by google. The question is Why is it still in the marketplace?
The second question, why a product that may potentially be laced with malware (it is signed with md2/rsa) is in the marketplace?
and the third question is: how is the default repo determined by the search box in Eclipse (under marketplace)?
Is my geolocation having any effect of how the Ecliplse Marketplace displaying results or what versions of extensions are being offered?
Would a search from Iran and search from USA yield the same results?
(no, I am not in Iran).
|
|
|
Powered by
FUDForum. Page generated in 0.09011 seconds