|
|
|
|
|
by wongarsu
733 days ago
|
|
If said Craigslist rando likes getting police visits and potentially being criminally liable for helping you commit a felony ... All code signing promises to give you the name of a real person or company that signed the binary. From there it's the end user's responsibility to decide if they trust that entity. In practice the threat of the justice system makes any signed executable unlikely to be malicious. But that doesn't mean you have to uncritically trust a binary signed by Joe Hobo |
|
What threats are those? Where are all the people going to jail for falsely signed software? The stuxnet authors seem to be in the wind.