Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Windows code-signing tweaks sure to irritate software developers (Hardware Certs? Huh?)
The Register ^ | Jan 26, 2017 | John Leyden

Posted on 01/27/2017 5:17:17 AM PST by dayglored

Changes that mean signing certificates for Windows can only be sold in hardware form – or from an as-yet undefined cloud-based "service” – from the start of February are likely to have a big effect on software development.

US trade body the Certificate Authority Security Council decided in December that "best practice" for code-signing certificates was to embed them in hardware devices, a policy endorsed with upcoming changes from Microsoft that kick in next week.

This could present an upheaval for software developers, according to a Reg reader who flagged up the story and asked to remain anonymous.

"ISVs who need to buy new certificates may find themselves having to revise their build processes," our anonymous tipster said. "It's interesting that one-man-and-a-dog shops won't be especially affected by the procedural changes, but will complain about the approximate doubling of certificate prices. Meanwhile, large ISVs with automated build-and-test systems won't especially worry about an extra few hundred pounds, but may have to revise their processes a lot."

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: codesigning; microsoft; windows; windowspinglist
This is likely to be a pain in the patootie, but it's probably a good idea. I think.

Code-signing is a big deal, very high security, usually with a signing server that's hidden off in a corner of the network and highly protected from everything except code-signing requests.

1 posted on 01/27/2017 5:17:17 AM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
This one is for the software developers ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 01/27/2017 5:17:59 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

“best practice”

After 35 years of programming, I note that anyone using the term “best practice” should not be asked near source code.


3 posted on 01/27/2017 5:27:51 AM PST by ctdonath2 (Understand the Left: "The issue is never the issue. The issue is always the Revolution.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: ctdonath2

asked = allowed


4 posted on 01/27/2017 5:28:27 AM PST by ctdonath2 (Understand the Left: "The issue is never the issue. The issue is always the Revolution.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

Doesn’t do anything for code correctness though.


5 posted on 01/27/2017 5:42:12 AM PST by Ray76 (DRAIN THE SWAMP)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ctdonath2

Hear, hear!


6 posted on 01/27/2017 5:43:33 AM PST by Montana_Sam (Truth lives.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Ray76
Doesn’t do anything for code correctness though.

Bingo! And if the code is poorly designed and weak it can still be exploited. All the Certs do is make it more likely the threat will come from inside instead of outside, and the true adversaries will adjust and account for that.

7 posted on 01/27/2017 5:54:05 AM PST by commish (Freedom tastes Sweetest to those who have fought to preserve it!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Ray76

The biggest problem (at least attributable to a platform) on Windows is malware. Code signing assures that, while the code may be crap, you know whose crappy code it is.


8 posted on 01/27/2017 6:07:52 AM PST by ctdonath2 (Understand the Left: "The issue is never the issue. The issue is always the Revolution.")
[ Post Reply | Private Reply | To 5 | View Replies]

To: dayglored
"embed them in hardware"

Made by whom?

There is such a thing as a hardware backdoor.

https://www.wired.com/2016/06/demonically-clever-backdoor-hides-inside-computer-chip/

And the cloud bit just sounds like a way to give gov access to everyone.

9 posted on 01/27/2017 7:25:25 AM PST by fruser1
[ Post Reply | Private Reply | To 1 | View Replies]

To: fruser1

You can just write a device driver that tells the kernel I’m a device of type x and voila you have a ‘hardware’ dongle.


10 posted on 01/27/2017 7:55:52 AM PST by pierrem15 ("Massacrez-les, car le seigneur connait les siens")
[ Post Reply | Private Reply | To 9 | View Replies]

To: ctdonath2; dayglored; Ray76; commish; fruser1; pierrem15

“best practice”; “Code-signing”; “code correctness” - “poorly designed and weak”; “hardware backdoor”; “write a device driver”.

This just goes to prove that no matter how hard Microsoft tries to be the “Ultimate Control Freak”, someone somewhere will always come up with “a better idea”. LOL


11 posted on 01/27/2017 3:55:03 PM PST by RebelTex
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson