http://rogerbinns.com/ ([identity profile] rogerbinns.com) wrote in [personal profile] mjg59 2011-10-19 06:31 pm (UTC)

It isn't secure

There is still a fundamental problem with all this. Anything that is appropriately signed is allowed. It would be an astonishing accomplishment for there to be the first piece of software ever that is bug and security hole free. For a bad guy to break into the system all they have to do is downgrade to signed code with a bug/security hole.

Unless of course you add something preventing downgrades which itself would also have to be bug free.

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org