10 ms·
Leaked stolen Nvidia cert can sign Windows malware
- pintxo 5y agoIf a corp like Nvidia cannot manage to store Code signing certs on hardware only, the whole process is broken beyond repair. What’s the value of signed code going forward?
- ddtaylor 5y agoDefense in depth.
- postalrat 5y ago10 layers of weak defenses should be enough for anyone.
- Genbox 5y agoThere is a hint of frequency illusion here. Millions of code signing certificates are stored securely on hardware devices or by other means. A leak of a private key every now and then does not negate the security of the entire ecosystem.
- pintxo 5y agoIs there any proof that most others store their certificates on hardware?
- gruez 5y agoHardware tokens are mandated for EV code signing certificates[1], but not for regular certificates. However, the certificate was from a while ago so that requirement probably wasn't a thing back then. [1] https://www.digicert.com/signing/code-signing-certificates https://www.digicert.com/signing/code-signing-certificates "REQUIRES TWO-FACTOR AUTHENTICATION USING HARDWARE TOKEN"
- Genbox 5y agoWhat gruez said is correct. Hardware token have been mandated for EV certificates for a long time by providers to prevent leaks. I'll also add that Amazon Key Management Service, Azure Key Vault, and Google Key Management Service store several hundred million private keys combined with no leaks so far (they are non-exportable and access is audited) It is very rare that we see malware signed by a publisher's certificate, which is why it is in the news every time it happens.
- hulitu 5y agoNo leaks does not imply security.
- native_samples 5y agoI bought a Windows EV code signing cert just months ago. It comes in the form of a password protected USB token.
- jimmaswell 5y ago> What’s the value of signed code A part of the roadmap to only allowing average users to execute native programs their overlords approve of. We're already sadly most of the way there with the scary dialogs and dark patterns anyone has to navigate to run anything unapproved.
- imglorp 5y agoThe benefit of signed code is it grants hardware vendors a perpetual control, gatekeeping, and rent seeking role. It was never your hardware. The cover story was security, which might be mathematically correct but in practice has been shown false in every way. Look how much malware gets signed and shipped on devices and sold on app stores: the vendor gets their cut, /shrug. Look how many devices have been intentionally bricked to force new sales - yay them again. And then there's the certificate management illusion.
- gruez 5y ago> The benefit of signed code is it grants hardware vendors a perpetual control, gatekeeping, and rent seeking role. It was never your hardware. but in this case it's literally not caused by hardware vendors ? They're not even a party to this arrangement. The requirement is being enforced by windows, and the certificates are issued by various CAs. If you don't want that just use linux or something, or disable signature enforcement within windows.
- krastanov 5y agoMost linux distros have used signed repository packages since forever, right? Not really challenging what you are saying, rather asking whether this is not already a very similar setup. I guess it is a social web of trust among package maintainers as opposed to the certificate authority root of trust in Windows. Or am I making a flawed comparison?
- imglorp 5y agoLinux lets you ignore signatures if you prefer. There are plenty of devices that don't.
- AshamedCaptain 5y agoYou cant disable signature enforcement on Windows. You can test sign and only if you disable secure boot and enjoy desktop watermarks.
- PragmaticPulp 5y ago“If it can’t be 100% perfect then what’s the point” is one of my least favorite arguments. A single or even multiple breaches doesn’t suddenly remove all value from all other code signing models.
- kevingadd 5y agohttps certificates leak all the time and we still use https. Something is better than nothing. Now, is it worthwhile to use code signing certs to try and certify the identity of the author? Maybe not, it was slowly phased out for https. But we certainly need something because the alternative (just download and run whatever) was tried and definitely did not work out. We don't want grandma doing the equivalent of 'curl http://x http://x | sudo bash' 4 times a week.
- blablabla123 5y agoI don't get why companies that large would bother considering not using HSMs. Basically it's about public-key encryption, even if https is not ideal, it's quite a widespread implementation that can be sufficiently secure for many use cases
- kevingadd 5y agoMy understanding is that HSMs are a requirement, and the leaked certificate predates it.
- hulitu 5y ago> We don't want grandma doing the equivalent of 'curl http://x http://x | sudo bash' 4 times a week. That's why we have web browsers running untrusted remote code.
- Schroedingersat 5y agoYou put they keys in the owner's hands with a method of changing them that can only he done with physical access.
- linster 5y ago"what's the point of laws so complex criminals can't understand them? They'll be broken anyway"
- stuu99 5y agoSigned binaries use will come into being with trusted computing, they are embedding Denuvo in the operating system, aka future compilers will allow game companies and companies like autodesk to sign their exe's and the exe's if cracked can be added to a list that windows 11 can force update the bios to add these cracked exes to a list that will refuse to run. That's the gist of trusted computing they are building an alternative internet/mainframe computer inside yours that they only have access to. Where have you been the last 23+ years? The videogame industry has been stealing PC games since 1997 with ultima online. Hear it from the dev's themselves. Don't think MMO's killed local PC games? Listen here kids. https://youtu.be/lnnsDi7Sxq0?t=1134 https://youtu.be/lnnsDi7Sxq0?t=1134 EA killed ultima 9 when the UO beta got massive interest, that lead to the death of PC games as local applications, the industry from then on there was a massive war to back end all PC games, they couldn't immediately do that to quake and urneal because we'd been treated too good with Warcraft 1-3, Descent 1-3, Quake 1-3, and build engine games like Duke 3d. The entire industry has always wanted to kill piracy and Ultima online gave the entire industry the go ahead once they realized that many of our fellow programmers and gamers were irrationally stupid beyond their wildest dreams. Anyone playing quake and Descent at the time fear the loss of dedicated servers and level editors which used to come with the games, we knew if Ultima online was successful that Publishers would want to back end every fucking PC game and that's the end of the personal computer and the return of IBM and mainframe computing. "Signed exe's" and trusted computing is the return of mainframe computing of the 60's in new bullshit language but I don't expect the mmo/steam generation to do anything but froth at the mouth. When they were the ones killing gaming and gave birth to microtransactions. You can't put MTX in diablo 1, warcraft 1-3, or starcraft 1 because they are local applications that run entirely from your pc. None of the code has been stolen out of the game carved back behind a user account and login requirement. Like with most PC games these days. We're losing gaming history and generation mmo is to blame for their general cluelessness of the evil of mainframe computing.
- bratwurst3000 5y agoHmmm maybe i should keep windows offline for a few days…..
- gchamonlive 5y agoI always use opportunities like this to experiment with whatever workflow I have on Linux to see what state it's at. I just game on Windows and do work on Linux so for me the transition is always quite simple: just install what you want on Steam/lutris and compare performance. Last time I was starting vanishing of Ethan Carter, but even though it was playable, the experience wasn't free of stutters, whereas windows ran flawlessly. In any case, it is always nice to jump back and check out how far Linux has come.
- Genbox 5y agoA stolen code signing certificate affect Linux in the same capacity as Windows. I'm of course ignoring the fact that a lot of Linux distros still do not have Secure Boot enabled by default, and therefore do not enforce any kernel driver signing policy.
- chousuke 5y agoHuh? I don't know what you consider "Linux distros", but Fedora has had SB working and on by default for quite a while now.
- Genbox 5y agoSure, Fedora has Secure Boot. So does Ubuntu, Debian and FreeBSD. According to DistroWatch[1], 26 Linux distros out of 927 have built-in support for Secure Boot, so I stand by what I said. [1] https://distrowatch.com/search.php?pkg=shim&relation=lessequal&pkgver=1&distrorange=InAny https://distrowatch.com/search.php?pkg=shim&relation=lessequ...
- scns 5y agoI bet he meant the small ones instead of major distros i.e. Red Hat/Fedora, Ubuntu, SUSE.
- ramshanker 5y agoThis would be revoked soon enough right?
- encryptluks2 5y agoProbably not as revoking would likely break NVIDIA drivers.
- willis936 5y agoOh well. They should be revoked ASAP anyway. Old releases can be re-signed then re-downloaded. Any situation where certs cannot be revoked for any reason is bad.
- encryptluks2 5y agoThe problem is re-downloading. I think this will take some time.
- native_samples 5y agoVery unlikely NVIDIA have been signing with an expired cert for 5 years. The real reason this is problematic is that Windows kernel driver signing wasn't complete before 2015. For signing (of anything) to be robust, it must be paired with a timestamping server. The signature then has these components: 1. The signature itself. 2. The certificate. 3. A data structure containing a hash of the signature, and a timestamp, signed by a timestamping authority. The purpose of (3) is to prove when the signature was computed, which in turn means that signatures can live longer than the certificates themselves. Note that normal Windows (and Apple) code signing for user space gets this right for a long time. Apparently Windows didn't in kernel mode until 7 years ago. Introducing timestamping isn't all that easy. If you stop accepting signatures because the underlying certificate expired, then you just put a time bomb in everyone's computers. So Microsoft had to allow the usage of expired certs and hope they'd never leak. They (eventually) lost that bet and the cert will now be revoked, but it won't have been used for many years so probably the overall damage is small.
- h2odragon 5y ago
- gjsman-1000 5y agoWell, that is... an interesting leak, but not exactly the types of certificate that this hacker group was treating to release on Friday.
- can16358p 5y agoI think they are "showing their teeth" cuing that it's just the beginning. An interesting leak from a entity with a very interesting request in the first place.
- asah 5y agoFor keys issued 6+ years ago... https://twitter.com/BillDemirkapi/status/1499735326406938625 https://twitter.com/BillDemirkapi/status/1499735326406938625
- themusicgod1 5y agoAs opposed to the regular nvidia cert which normally signs windows drivers (ie drivers for malware)? This is a total non-story
- IYasha 5y agoBut... can we haz better Linux drivers after this? :)
- deleted 5y ago[deleted]
- AshamedCaptain 5y agoFinally I can develop and publish open source drivers for Windows again. Guess someone out there still believes that windows code signing is a security feature rather than just a way to keep the smaller developers out of the ecosystem.