On The Insider: Michael Jackson Tops Yahoo Search
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 4:
Next »
Sign your updates!
Devs, sign your updates!

The good news is that this is for applications, not the OS or drivers. Windows updates are signed.

This is one area where having the 64 bit version can be a real advantage: In Vista, 64 bit drivers are required to be signed, but 32 bit drivers are optionally signed. I have no idea if Windows 7 makes signing mandatory for all drivers.

OS updates are always signed.

The bad news is that updates are generally somethings users trust, and will generally be something that users allow past a UAC prompt. So if they can hijack an unsigned application update - they're potentially getting admin privileges.

So application devs - time to sign your updates!

Same should probably go for addons and plugins for applications as well.
Posted by: CobraA1   Posted on: 08/03/09 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Sign your updates!  CobraA1 | 08/03/09
Signing just verifies identity, but not correctness  Patanjali | 08/03/09
This begs the question....  kraterz | 08/03/09
RE: Researchers hijack computer during software update  dcnblues | 08/03/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here