(I thought calibre plugins are mirrored on the calibre website. So at least it is only vulnerable between your server and MobileRead, when you scrape the index for updates. At least that is my justification for saying Debian is silly for calling the plugin updater a massive security hole and disabling it universally.)
I too would like to see MobileRead use HTTPS.
|