On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 3:
Next »
Signed is not the same as safe
As this incident clearly shows, signing of applications is not a guarantee of safety. A digital signature tells you that program has not been tampered with since it was signed and who signed it. It does not tell you that the creator had your best interests at heart nor does it tell you that the signer knows every byte of the application and what it will do. In the case of Symbian Signed applications there is also a security check but no check is perfect. Even if every application was checked by a human researcher mistakes would still happen. Humans are, after all, human.
As my colleague at Sophos, Paul Ducklin, wrote strong authentication cannot eliminate fraud. http://www.sophos.com/security/technical-papers/phishing-and-fraud.pdf
Signing is an identification technology, not a guarantee of security.
Posted by: richardwang   Posted on: 07/23/09 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Signed is not the same as safe  richardwang | 07/23/09
How are apps verified before signing?  kraterz | 07/23/09
RE: The future of mobile malware - digitally signed by Symbian?  j0nnysmith | 07/31/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement
  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More