3 ms·
If you can convert data into an API call, then it becomes an issue of steganography. The only way to trust a binary is through 100% code coverage through all po
by musesum 4y ago
If you can convert data into an API call, then it becomes an issue of steganography. The only way to trust a binary is through 100% code coverage through all possible inputs, which is intractable.
Code signing and a secure enclave may help protect against local use cases, like ransomware, but doesn't protect against hybrid attacks, like granting access to 3rd parties.
Maybe this means that all binaries in 2040 should be derived from open source with AI doing the threat detection.