Reply to post: Re: Certificates

Researchers claim ISPs are 'complicit' in latest FinSpy snooping rounds

alain williams Silver badge

Re: Certificates

But were the packages not signed with the public key of the software vendor/distributor ? Or are we dealing with a bunch like slack ?

OK: I don't know how this is done in the windows world, and if you have never installed anything from the vendor you will not have the key (so getting it could be spoofed) ... but Skype is from Microsoft and so the Windows machine will have their signing key ... so if the installer does not complain we need to ask how the spooks got their malware signed to make it look legitimate.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon