Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Question:

Question: Insecure update error! DSA key. Sparkle

When I open Mail I receive a pop up - "Insecure update error! For security reasons, you need to sign your updates with a DSA key. See Sparkle's documentation for more information". I believe this is the result of me adding a new Plugin to Mail. I like the Plugin. How do I permanently remove this error message? I searched for information about Sparkle and I don't it is something I need, or want.

Posted on

Reply
Question marked as Solved
Answer:
Answer:

Sparkle is a software library used by many application developers as a means of distributing updates to their applications automatically over the Internet. However recently some security vulnerabilities where discovered in older versions of Sparkle.


See https://sparkle-project.org/documentation/security/

and http://arstechnica.co.uk/security/2016/02/huge-number-of-mac-apps-vulnerable-to- hijacking-and-a-fix-is-elusive/


Some corporates IT departments may have taken steps to block/disable Sparkle as a brute-force means of 'fixing' this security issue.


Rather than relying on the vulnerable version of Sparkle to update your application or in this case plugin with presumably also a new fixed version of Sparkle you should check on the authors website and manually download and install a new fixed version.

Posted on

Question marked as Solved

Feb 29, 2016 4:39 AM in response to barrygou In response to barrygou

Sparkle is a software library used by many application developers as a means of distributing updates to their applications automatically over the Internet. However recently some security vulnerabilities where discovered in older versions of Sparkle.


See https://sparkle-project.org/documentation/security/

and http://arstechnica.co.uk/security/2016/02/huge-number-of-mac-apps-vulnerable-to- hijacking-and-a-fix-is-elusive/


Some corporates IT departments may have taken steps to block/disable Sparkle as a brute-force means of 'fixing' this security issue.


Rather than relying on the vulnerable version of Sparkle to update your application or in this case plugin with presumably also a new fixed version of Sparkle you should check on the authors website and manually download and install a new fixed version.

Feb 29, 2016 4:39 AM

Reply Helpful (2)
User profile for user: barrygou

Question: Insecure update error! DSA key. Sparkle