I have released an update 5.1.0 build 3824 to better protect our users from any future dns hi-jacking attempts.
Below are some of the specific changes I've implemented
When preforming an update check the update check reply messages now include a digital signature, if the digital signature is missing or invalid then the server reply is discarded.
FlashFXP will only process the server reply if the digital signature can be verified.
After downloading the program updates additional checking is performed to ensure that the digital signature is owned by us, if the digital signature fails validation or doesn't match then the downloaded content is deleted.
|