I went to download the latest firmware for my router and noticed the download link is not HTTPS, so I sent the following email to the manufacturer:
I went to look for new firmware for my Archer C7 router, but I saw that the download link is over unencrypted HTTP, not secure HTTPS. I would never download software or firmware over an unsecure connection. Please upgrade your site to HTTPS.
This was their reply:
The device will verify the integrity and correctness of the bin file, if it is tampered, it won't be able to upgrade successfully. Don't worry, you can download it.
Ignoring the fact that they have no excuse for not using HTTPS, my question is: Is it even possible for the router to confirm that a new firmware file hasn't been tampered with? How would that work?