What could a TLA do with this if it had time to plan ahead?
Serve malicious updates from a locally controlled machine, for one. Lord knows about auth.
Wouldn't they have to break into my local machine first, plant an update service, and an update? That doesn't seem to scale well at all, and wouldn't it be easier to just break into the machine they want to 'update'?