#signing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #signing, aggregated by home.social.
-
-
The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.
The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.
So my questions are:
a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?
b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.
[1] Am I the only one who used to sell their stuff when they used their full name?
[2] Only with #Windows, natch.
[3] I'll start calling programs "apps" when I'm dead, thanks.
#LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware
-
Wandelend in #Amsterdam valt in de Binnen Brouwersstraat dit naambordje gelijk op | When walking through Amsterdam, this nameplate immediately catches the eye in Binnen Brouwersstraat.
#signing #typographic #typematters #fontlove #Typographymatters #typographyinspired #typographydesign #typographyart #typedesign #goodtype #WorldofType -
The many named Max app and video streaming service has a new trick tonight: #ASL programmes! I've got the Superman movie playing with a mel person animatedly #Signing the whole thing in the bottom right corner of the screen. He's amazing!
Kal-El was yelling at his dog STOP STOP SIT SIT STAY 😸😹 and then there was some foley *whooshing and booming* . Your move, Netflix. -
One of the many reasons you should sign your git commits:
https://github.com/OpenSourceMalware/PolinRider
in short: infects your code via a malicious VS Code extension or NPM package, which in the end overwrites your last commit. You might never notice. But what it cannot do: sign that commit (as it does not have your key phrase). So a sudden unsigned commit gives you a chance to spot that "something weird happened".
-
You're still signing data structures the wrong way
https://blog.foks.pub/posts/domain-separation-in-idl/
#HackerNews #still #signing #data #structures #the #wrong #way #domainseparation #datamodels #security #bestpractices #coding
-
Essential Security Check for Windows File Signing 🔒 https://www.youtube.com/watch?v=Q32E3lgikCw 🎬💡 #Microsoft #Security #Check #Signing #Guide