as I understand it the binary would be inspectable and comparable to the original, there would be a signature portion added which is a kind of hash of the binary and the signing key, which can be verified against the public portion of the Microsoft key and the binary itself. No real scope for Microsoft to return a modified binary.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
signed doesn't mean encrypted
Date: 2012-05-31 07:50 am (UTC)