|
Not sure what's so unexpected about that? You get the entire calibre program from the same server (group of servers), if someone compromised the developer (me) they could just as well serve you compromised calibre binaries in the first place.
And it uses a self signed certificate deliberately, precisely so no third parties other than me are in the network trust chain.
FYI various network facing bits of calibre are dynamically updated recipes, get books, metadata sources etc etc. and have been for a decade plus.
|