4 ms·
It needs to exist in an untrusted environment.. it verifies that the driver which has low level access to the computer hasn't been modified by a third party.. M
by cyrix281 9y ago
It needs to exist in an untrusted environment.. it verifies that the driver which has low level access to the computer hasn't been modified by a third party.. MS signed system binaries are the same way; it's a safeguard against malicious entities.
- wtallis 9y agoI'm not arguing against the entire concept of driver signing, just one specific nuance of Microsoft's driver trust model. There is a place for driver signing and signature checking, but de-trusting a driver that you were perfectly happy to give kernel-level access yesterday doesn't make sense.
- zaarn 9y agoIt's still Oculus fault because they didn't use a timestamped signature. A timestamped signature on the binary would have it kept working and that's how MS intents it to work. You can leave it out if you have the desperate longing for having your software break suddenly without reason like Oculus just did.
- gmueckl 9y agoAnd that's where MS is at fault: drivers without timestamped signatures should be treated as faulty. This would prevent these errors in the first place.
- tallanvor 9y agoI guess I can see reasons why some companies may want to be able to produce time-limited drivers: Maybe they want beta versions to stop working, forcing users to upgrade. For offline computers, it might be that some companies would see this as a way to enforce contract periods (customers would have to install an update to continue using the product when their contract is renewed). Of course, disabling driver signature verification is still a way to bypass that, but often times the companies that do things like this probably aren't thinking about that.
- mathieubordere 9y agoMaybe the API should then explicitly ask for a 'timestamp-none' in case the driver needs to be time-limited, forcing the developer to at least think about it.
- marcosdumay 9y agoDo you have any reason that is good from the point of view of the computer owner? (You know, the one sending money to Microsoft.)
- sleepybrett 9y agoThen they can write it into the driver "Stop working on jan 1 2019"
- zaarn 9y agoThere are usecases for signatures without timestamp. Besides, literally every codesigning blogpost/tutorial/guide/etc I found tells you to use a timestamping server so the guys and girls and Oculus must have skipped the critical parts of whatever they used.
- gmueckl 9y agoWhat is a legitimate use case for a binary deliverable without a timestamped signature?
- zaarn 9y agoAs you might have guessed, when you don't want someone to use a binary beyond a certain date. Security Solutions could benefit from this, the customer will have to update or disable the signature check if their version of the solution becomes too old. Old versions could open them up to vulnerabilities. Another might be when you distribute beta or testing versions of your software. The customers can safely test the version and the lack of timestamp prevents them from running it in production permanently. They have to update to the release version. It could also be useful when you sell a software to a business and want them to test it first. So you send them the program without a timestamp signature and limit the validity of the certificate. That way they can't just run the test version forever. Really anywhere where all parties involved, user and producer, do not want to run a binary forever but the producer might not fully trust the user to do that.
- gmueckl 9y agoThe customer can always re-sign the binary if they wante to and replace the existing signature. A time limited inside the program code would be more secure.
- agar 9y agoFor what it's worth, I think this is a very sane perspective.