4 ms·
"Thankfully, our digital signatures are lost in the process, so that's reassuring." So you mean the software has been digitally signed? If it is signed how is
by MPlus88 4y ago
"Thankfully, our digital signatures are lost in the process, so that's reassuring."
So you mean the software has been digitally signed? If it is signed how is it possible that it is cracked? Isn't even a slight modification of the binaries will render the software unusable if it is signed? I have a software that is signed digitally and the certificate private/public key is supposedly takes some hundred billion years on average to crack. So what is the point of signing a software?
- yakkityyak 4y agoPeople who download pirated versions will just clickthrough the trust warnings that the .exe or whatever is not signed.
- TheAdamist 4y agoSigning the software protects against tampering and attests that it came from who signed it. There are some systems that require signed applications before they allow them to run, but most systems dont. Signed drivers are more frequently required than applications. Cracking tampers with the binary, so the signature is removed.
- MPlus88 4y agoThe way I understand it is a signature is included in the binaries and when run the software will hash the binaries and the result is compared to the signature. If the two don't match the software has been tempered and the software won't run. If it is that easy to remove the signature then what is the point of signing a software? It will be like your first floor home has a steel door but the window is wide open.
- remexre 4y agoI think this is the OS-level signature verification; so the OS (possibly with nudging) will still allow you to _run_ the binary, but won't say "this is from FooCorp" and may nag the user on startup "this is a potentially untrustworthy binary"
- huhtenberg 4y agoA signature can be stripped off a binary, usually using the same tool that is used to add it.