Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Of course they could have separate signing certificates for 'overriding' drivers, but that would be just as much a hack as using the time stamp."

It'd be far less of a hack, IMO. At least that particular hack wouldn't be totally subverting something with as much predefined semantic meaning as a timestamp.

Besides, it could actually fit into Microsoft's organizational structure reasonably well. The team that maintains default drivers could have one signing key, and the team that maintains override drivers could have a different signing key. Same deal for Microsoft teams/departments that develop/maintain drivers for Microsoft hardware projects (like Microsoft-branded HIDs).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: