"Of course they could have separate signing certificates for 'overriding' drivers, but that would be just as much a hack as using the time stamp."
It'd be far less of a hack, IMO. At least that particular hack wouldn't be totally subverting something with as much predefined semantic meaning as a timestamp.
Besides, it could actually fit into Microsoft's organizational structure reasonably well. The team that maintains default drivers could have one signing key, and the team that maintains override drivers could have a different signing key. Same deal for Microsoft teams/departments that develop/maintain drivers for Microsoft hardware projects (like Microsoft-branded HIDs).
It'd be far less of a hack, IMO. At least that particular hack wouldn't be totally subverting something with as much predefined semantic meaning as a timestamp.
Besides, it could actually fit into Microsoft's organizational structure reasonably well. The team that maintains default drivers could have one signing key, and the team that maintains override drivers could have a different signing key. Same deal for Microsoft teams/departments that develop/maintain drivers for Microsoft hardware projects (like Microsoft-branded HIDs).