The Channel logo

Security risk, O RLY?

Let's say MS produces buncha' patches, and some third-party wants to distribute them. Now there's the obvious possibility that this very evil and untrustworthy third party tampers the patches to include some malware. How possibly could MS protect its customers?

Maybe by publishing list of checksums for all the patches published? How about MD5? The algorithm is free of royalties, and quick to compute.

Or, even better, could MS supplant each patch with a digital signature, to be verified during installation of the patch?

Is that a rocket-science to MS developers? Or did MS overlook it totally on some purpose...?

Forums

Forgotten password

Opinion

euros_channel_money

Tim Worstall

Time to take a sniff at the coffee, perhaps
joe_tucci_emc_channel

Chris Mellor

Will they have to drag him back like last time?
chain_relationship_channel

Features

cloud_accounting
Playing the SLA long game
channel_teaser_money_top
cloud computing Fight
Applications must work for the cloud to float
Paul Cormier, Red Hat
How a Unix killer crawled from the dot-com bust