2 ms·
Then what's the purpose of signing in the first place? The keys for official releases are supposed to be kept by a trustworthy senior management or some people
by e3b0c 11y ago
Then what's the purpose of signing in the first place?
The keys for official releases are supposed to be kept by a trustworthy senior management or some people with highly restricted privilege. Also the software/firmware shipping process must be well audited if there are serious (not just pretending to be) security requirements. The keys should not be exposed to a random technician or a new hire who can possibly responsible for destroying your and your clients' businesses. It looks like they didn't have a quite "formal" shipping flow at least in this case.