What Happens When a Code-Signing Key Is Stolen?
Code signing is used to help software companies demonstrate that an application, update or driver is from a trusted source and hasn’t been modified since it was released. The system relies on a private cryptographic key that only the legitimate publisher should have access to. If the key is stolen, attackers might be able to make malicious files appear as authentic – a real software supply-chain risk.
To appreciate the potential damage that can occur when someone steals a private key, it’s important to first answer the question of ‘What Is Code Signing?‘. Code signing establishes a digital signature that associates software with its publisher. An operating system and security software can verify that signature before permitting the file to execute. If an attacker can steal a key, he can impersonate that trusted identity.
Attackers Can Make Malware Look Legitimate
Unsigned software can be identified by OS, browsers...
Copyright of this story solely belongs to cloudcomputing-news.net. To see the full text click HERE