Toot

Written by Jeffrey Yasskin on 2024-10-17 at 17:21

@chrisneedham A native editor app cannot include its signing cert when distributed to customer machines, even if it's closed source. :) If that signing cert is trusted, and the software has restrictions that a malicious user might want to get around, the signing cert will quickly be extracted and used to sign content generated without those restrictions.

If the WG thinks they're going to safely distribute signing keys in software, we need to get them some security review ASAP.

=> More informations about this toot | View the thread | More toots from jyasskin@hachyderm.io

Mentions

=> View chrisneedham@w3c.social profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113323919911144275
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
223.458481 milliseconds
Gemini-to-HTML Time
0.280304 milliseconds

This content has been proxied by September (3851b).