TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

An analysis of iOS 5 OTA updates by innoying

6 点作者 dpearson超过 13 年前

1 comment

adamjernst超过 13 年前
<i>As it turns out, it’s just HTTP requests. The alarm bells should be going off now. So you’re telling me that the part of the O.S. that runs as root and replaces system files is downloaded via unsecured, unauthenticated HTTP? Yup.</i><p>Well, I'm not sure it makes a difference. As he later points out, update packages are signed by Apple, so unless you have access to Apple's private key you can't make an update package that will actually be installed.<p>Using HTTPS instead of HTTP would be wise, but in the end it doesn't make a difference.<p>On the whole though, this is a fascinating exercise. Thanks!