Survivable Key Compromise in Software Update Systems¶
Samuel, J., Mathewson, N., Cappos, J., & Dingledine, R. (2010). Survivable Key Compromise in Software Update Systems. Proceedings of the 17th ACM Conference on Computer and Communications Security, 61-72.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Artifact Signature Verification
- … signature proves the key signed the bytes, not that the artifact is benign.** If the signing key or the signer is compromised, a perfectly valid signature ships a hostile payload — the classic supply-chain move, where defenses work exactly as configured yet admit the attack because it wears trusted credentials.
This sourceTreats signing-key compromise as a threat that can authorize malicious software updates despite otherwise valid authentication.
- … signature proves the key signed the bytes, not that the artifact is benign.** If the signing key or the signer is compromised, a perfectly valid signature ships a hostile payload — the classic supply-chain move, where defenses work exactly as configured yet admit the attack because it wears trusted credentials.
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:b641b424fbc2 · see in the full table