|
|
|
|
|
by abalone
3770 days ago
|
|
Conjecture: Isn't Apple's private signing key already a "master key to turn 100 million locks"? I.e. the key they use to sign software updates. With that key, someone could create malware and sign it... Apple creating the malware just saves them a step. Ergo the "target on that piece" is already pretty high value, yet Apple is able to keep it secret / prepared for contingencies (like rotating the key..) Thoughts? |
|
This is a problem for signing software, but also things like updating their webpage and content on the App Store. All these systems need to have authentication data exist, and if lost to people with malicious intent it could be lost.