Does SourceTree really download embedded Mercurial over non-encrypted channel?

Hi there,

I just installed SourceTree and it asked me whether I'd like to use an embedded version of Mercurial or if I'd like to download it manually. I chose the former because I'm lazy, but as far as I could tell from the download dialog, Mercurial was actually downloaded over a non-encrypted channel.

Is that really true?

2 answers

It may be true. Why does it matter? I don't think Mercurial's executbles and libraries contain any of your sensitive or private information.

It matters because SourceTree could be downloading arbitrary data from the Internet without verifying the source. For instance, I could be at a coffee shop or conference where I don't control my connection to the Internet and a malicious user could be feeding me a bad package.

It's like saying we should have strict security at the airport and prevent people from bringing water bottles into the terminal, but also that we don't really care to screen any of the vendors selling water bottles inside the terminal...

To top this off, imagine I had just installed SourceTree via the provided installer and that SourceTree had subsequently been launched by that installer. The installer probably ran as Administrator on my machine, so unless the SourceTree devs were extra careful, this means SourceTree will now shell out to the downloaded Mercurial binaries with Administrator privileges. You can probably see why that's bad if the package didn't actually come from Atlassian's servers. :)

Suggest an answer

Log in or Join to answer
Community showcase
Brian Ganninger
Published Jan 23, 2018 in Sourcetree

Tip from the team: workflow and keyboard shortcuts

Supported Platforms macOS Sourcetree has a lot to offer and, like many developer tools, finding and using it all can be a challenge, especially for a new user. Everyone might not love ...

260 views 0 3
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you
Atlassian Team Tour

Join us on the Team Tour

We're bringing product updates and pro tips on teamwork to ten cities around the world.

Save your spot