4 ms·
If the attackers would have used their own name/email linked to a GitHub account and signed the backdoor commits, GitHub would display a green "Signed" label, a
by trulyrandom 6y ago
If the attackers would have used their own name/email linked to a GitHub account and signed the backdoor commits, GitHub would display a green "Signed" label, and everything would look OK to an outsider.
- megous 6y agoThat's why it's just a gimmick. Signing only works as protection against hosting compromise if the signing/verification is separate from the hosting itself. Someone responsible for release would have to manually keep a list of keys of authorized comiters and check the repository against this list at the very least prior to a release.
- kenmacd 6y agoIt's not about the green label. A set if commits signed by some unknown person is a lot easier to spot and clean up. Looking at these commits they say mid-2017. Without signatures any previous commit could be by the same author.