Who runs UUP dump—how susceptible to a supply chain attack is it?


Baeolophus

Well-known member
Member
Local time
8:56 AM
Posts
170
OS
macOS Sequoia
For a few years now I have gone to the UUP dump site to download the latest build of Windows 11 and run their script to generate an ISO image. I would then use Rufus to copy it to a USB flash drive and use that to install Windows on a computer. This has worked extremely well for me.

With the rise of supply chain attacks I am wondering,
  1. who actually operates the site,
  2. how well they would be able to protect themselves against being compromised,
  3. and how easy it would be to insert code into the script that would compromise every single Windows system installed with the resulting ISO?
It would seem to me that UUP dump would be a very attractive target to criminals and state actors alike who could spend a large amount of resources on that.

Unfortunately, the downloadable media coming from Microsoft directly is very outdated.
 

My Computer My Computer

At a glance

macOS SequoiaM1 Max Apple Silicon32 GB
OS
macOS Sequoia
Computer type
Laptop
Manufacturer/Model
Apple
CPU
M1 Max Apple Silicon
Memory
32 GB
Back
Top Bottom