PDA

View Full Version : OT - keep your code-signing certificate secure



NewsArchive
09-29-2012, 06:42 AM
No idea how this came about for Adobe... but not happy news:

http://www.adobe.com/support/security/advisories/apsa12-01.html

Jane Fleming

NewsArchive
09-29-2012, 06:42 AM
> No idea how this came about for Adobe... but not happy news:
>
> http://www.adobe.com/support/security/advisories/apsa12-01.html

Very funny (well, not really <g>). But someone was able to get access to a
so-called Adobe "build" server used for developing Adobe software and from
there sent a request to an Adobe code signing server. The original Adobe
code signing certificate was then used to digitally sign, or authenticate,
the malware as coming from Adobe. This means that the malware could
masquerade as a legitimate Adobe program, but Lips said this was not done.

Unbelievable!!!!

Friedrich