3 ms·
Remember that rogue driver signed by a “leaked” cert? Things like that are a lot more useful than fooling someone about some silly website. Updates to your OS
by inter_netuser 5y ago
Remember that rogue driver signed by a “leaked” cert?
Things like that are a lot more useful than fooling someone about some silly website.
Updates to your OS or secure apps (lmao) funded by the abc soup (Signal and Free Radio Asia, read up) could be signed by the government.
For the greater good, citizen.
- inter_netuser 5y agoDoes Chrome do certificate transparency on its own updates?
- dane-pgp 5y agoApps and OSes shouldn't (and don't need to) make their security dependent on the web PKI. Linux distros come with their own public keys, for example, which are used to check the signatures on package updates. Things have got a bit worse recently, with the Google Play Store requiring app developers to let it build and sign the packages itself[0], but I suppose the argument is that if you don't trust Alphabet with the app signing keys, you shouldn't trust it with the signing keys for the OS updates you download. (If your Android updates are signed by keys controlled by an entity other than Alphabet, then you can presumably use an alternative app repo too). [0] https://www.theregister.com/2021/07/01/android_app_bundle/ https://www.theregister.com/2021/07/01/android_app_bundle/