4 ms·
I would like to state quite firmly that releasing the signing keys is absolutely the wrong solution to this problem, because that destroys the security that cod
by asuffield 11y ago
I would like to state quite firmly that releasing the signing keys is absolutely the wrong solution to this problem, because that destroys the security that code signing was designed to create.
The correct solution to this problem is to release a tool for people to change the code signing certificates on their devices to ones which they control, and to arrange for this tool to require a reasonable level of physical access so that it cannot be used remotely. Then device owners can have code signing security on their own terms and be confident that only their own trusted builds can be pushed to their devices via remote updates, which is a super useful feature when you have more than two devices.