Switching the updater to utilize https in place of recent plaintext http might be great and easy initial step. It really is pleasant bonus if Additionally, it checks new exe's signature, but in first area, it should not let anyone on the way in which to intercept requests so quickly... Also tab excess - consider opening all choices applying that si