3 ms·
Will you notice if the software will be signed by certificate for "imagemaqick.com" or "imagemagik.com" or "imagemagick-developers.com"?
by codedokode 3y ago
Will you notice if the software will be signed by certificate for "imagemaqick.com" or "imagemagik.com" or "imagemagick-developers.com"?
- londons_explore 3y agoHopefully Windows will remember that I downloaded the file from imagemagic.com check that the certificate matches the place I downloaded it from... Although... As long as downloads are always provided from the official domain via HTTPS, and the OS can keep track of that, I don't really see why the executable itself needs to be signed...
- tremon 3y agoimagemagick.org imagemagic.com That's a good way to illustrate the GP's point. As long as downloads are always provided from the official domain via HTTPS You are conflating control over the public website with control over the build/signing infrastructure. A good defense-in-depth strategy means that a compromise of one should not lead to an automatic compromise of the other.
- yread 3y agounless they use a cdn with a hostname like imagemagick-14.akamai.net
- nolongerthere 3y agoMost OS software is downloaded from code repositories like github or fosshub to save on networking costs, not to mention CDNs that are often used even when the link is on the software's website the file itself will often not be "coming from" that website.
- brnt 3y ago> Most OS software is downloaded from code repositories like github or fosshub to save on networking costs, [X] Doubt Do not underestimate the sheer number of people jamming in software names or descriptions into Google and getting their wares on the likes of softpedia.
- nolongerthere 3y agosame difference though, that's the equivalent of a CDN or fosshub. Its definitely not the author of the software.
- mastax 3y agoAbout as well as id notice if the software were signed by - Benjamin Olafsson - Imagemagick Solutions Gmbh - Imagemaqick LLC - FutureSoft Inc It's very common for software to be developed by a company whose name bears no resemblance to the product itself. It's also common for small commercial or open source projects to be signed by an individual developer in their name. Am I going to verify any of these? In practice, no. If I wanted to verify the company name I'd visit the website I downloaded from and check the footer's copyright notice. Unless the website itself is EV validated (almost never) we're back to DV with extra steps. The only time I've ever looked into the signee is when I downloaded obvious malware from a fake version of GNU Cash's website which I found from a Google ad. The malware was signed with a certificate from a Taiwanese hardware company.