A mighty fortress is our PKI, Part II

Tom Ritter tom at ritter.vg
Fri Aug 6 20:38:54 EDT 2010


> And what else should Windows say?  "We put this through our time machine and
> noticed that at some time in the past it was signed and now it isn't"?

Absolutely, on initial install there's no way to know it was originally
signed (if you're smart about it).  But in another architecture
Microsoft makes available (ClickOnce) software _upgrades_ that _were_
initially signed - but now are not - do not give indication that
something fishy is going on.

-tom

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list