30 ms·
They don't use cryptographic timestamps with their signatures ? The certificate might now be invalid, but the signatures were done at a time when it was valid.
by M0 7y ago
They don't use cryptographic timestamps with their signatures ?
The certificate might now be invalid, but the signatures were done at a time when it was valid...
- fluidcruft 7y agoThe problem is that "time" is fungible and can be forged. The date on a signature doesn't really mean anything.
- userbinator 7y agoEmphasis on cryptographic timestamps.
- altfredd 7y agoThis is a very bizarre justification for an obvious bug. Code-signing does not work that way anywhere else — neither in Android, nor on iOS, Windows or any other common platform. There is a possibility that Mozilla implemented their backwards code-signing model on purpose — for example, it allows them to oust unwanted extensions without explicitly recalling their certificates. But personally I think that they just didn't give the matter enough thought.