Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But my point is that more teams needed access to signing keys because some of those teams were dedicated only to licensing issues. If they didn't need signing keys, those keys wouldn't have been compromised.

Cryptographically signed binaries are not used to manage licensing issues, they are used to make sure that no-one intercepts your download and replaces it with a malicious binary. It is absolutely essential that computer programs are signed or delivered through a secure connection.

Losing your signing keys will make the entire system jeopardized and new keys must be generated and securely transmitted (this is hard).

> To me, it is upsetting when the code to protect the vendor's interests is where a critical security vulnerability exists.

Yes, that would be upsetting if it were true. But it isn't. The whole system is in place to protect you, the customer.



The issue was that Microsoft left behind the ability to sign code with a Microsoft certificate by mistake.

The entire reason the attackers could use the certificate was because Microsoft left behind that functionality in the suite of software that allows enterprise customers to license their instances of Terminal Servers.

I am not railing against cryptographic signing as a concept -- what happened was Microsoft played fast and loose with their certificate chain in order to provide their customers with a way to prove that they had paid for software.

The certificate chain could have been a lot cleaner if that licensing bit wasn't necessary.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: