Skip to main content
Participating Frequently
October 26, 2016
Answered

get.adobe.com website certification

  • October 26, 2016
  • 2 replies
  • 502 views

I just got prompted to update my flash player on my mac running Safari 10.0.1

I followed the link to the update server at get.adobe.com and observed there was no padlock next to the website URL. I then followed the link through from google to the update server to make sure I was going to the right place and not a malicious website and still there was no padlock.

It seems the get.adobe.com website is using a SHA-1 certificate. Surely this is insecure and opens up a potential vulnerability? Especially on mac as users will frequently update their flash software with out a second thought and the process involves entering your administrator password.

    This topic has been closed for replies.
    Correct answer Satinder S Bains

    The certificate is upgraded to SHA256

    Thanks

    2 replies

    Satinder S BainsCorrect answer
    Participating Frequently
    November 25, 2016

    The certificate is upgraded to SHA256

    Thanks

    Participating Frequently
    October 26, 2016

    Hi James,

    We are aware of this and working on it. Would be updating the pages soon.

    Thanks