Hacker News new | ask | show | jobs
by denton-scratch 1917 days ago
It also means that if I modify it, it's no longer signed. And if the system is configured so that only binaries signed by Microosoft (or by a signer that Microsoft trusts) can run, then the modified software won't run.

Code signing is A Good Thing, in principle. But it's easily hijacked by bad actors to further monopolistic goals.

1 comments

It also gives a false sense of security. There have been supply chain attacks in the past that succeeded because the attackers got their hands on a cert and signed malicious code.