Does SourceTree really download embedded Mercurial over non-encrypted channel?

Hi there,

I just installed SourceTree and it asked me whether I'd like to use an embedded version of Mercurial or if I'd like to download it manually. I chose the former because I'm lazy, but as far as I could tell from the download dialog, Mercurial was actually downloaded over a non-encrypted channel.

Is that really true?

2 answers

It may be true. Why does it matter? I don't think Mercurial's executbles and libraries contain any of your sensitive or private information.

It matters because SourceTree could be downloading arbitrary data from the Internet without verifying the source. For instance, I could be at a coffee shop or conference where I don't control my connection to the Internet and a malicious user could be feeding me a bad package.

It's like saying we should have strict security at the airport and prevent people from bringing water bottles into the terminal, but also that we don't really care to screen any of the vendors selling water bottles inside the terminal...

To top this off, imagine I had just installed SourceTree via the provided installer and that SourceTree had subsequently been launched by that installer. The installer probably ran as Administrator on my machine, so unless the SourceTree devs were extra careful, this means SourceTree will now shell out to the downloaded Mercurial binaries with Administrator privileges. You can probably see why that's bad if the package didn't actually come from Atlassian's servers. :)

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Oct 23, 2018 in Sourcetree

Tip from the team: configure your repos for hosting goodness!

Supported Platforms macOS Windows We recently introduced support for additional hosting services such as GitHub Enterprise, GitLab (Cloud, Community Edition, Enterprise Edition), and...

1,214 views 4 2
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you