3 ms·
Since Shai-Hulud scanned maintainers' computers, if the signing key was stored there too (without a password), couldn't the attackers have published signed pack
by carols10cents 1y ago
Since Shai-Hulud scanned maintainers' computers, if the signing key was stored there too (without a password), couldn't the attackers have published signed packages?
That is, how does signing prevent publishing of malware, exactly?
- yawaramin 1y agoHow did Shai-Hulud get access to maintainers' computers?
- CaptainOfCoit 1y ago> if the signing key was stored there too (without a password), couldn't the attackers have published signed packages? Yeah, of course. Also if they hosted their private key for the signature on their public blog, anyone could use it for publishing. But for the sake of the argument, why don't we assume people are correctly using the thing we're talking about?
- lelanthran 1y agoIn past comments I said that a quick win would be to lean on certificates; those can't easily be forged once a certificate is accepted.