logoalt Hacker News

mr_mitmtoday at 9:14 AM4 repliesview on HN

What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.


Replies

sidewndr46today at 10:31 AM

Microsoft signed the Crowdstrike updates. I don't think a CA signing a piece of malware is a realistic thing to be concerned about.

megoustoday at 1:24 PM

Only signal is that whoever is in the subject DN (highly) probably signed the code. There's 0 signal about trustworthiness of the code in the signature. Thrustworthiness signal is in the behavior/reputation of the signer.

Pretty sure there were historically a lot of apps that stole peoples contact lists and were signed properly. Certainly in the Android world.

duskdozertoday at 10:13 AM

Is it some entirely different process than providing hashes and a GPG signature?

show 1 reply
Eldttoday at 9:26 AM

Misplaced trustworthiness?