Security package SC: doubt an unvouched publisher, report a changed signed file as tampered - #49
Merged
Merged
Conversation
…ed signed file as tampered A publisher name is read back from the certificate without walking the chain, so beside any verdict other than Trusted it is only what the certificate claims. A Microsoft file changed after it was signed keeps a real Microsoft certificate, and !publisher:microsoft - the audit question the field exists for - left out exactly that file with full confidence. - BinarySignature.VouchesForPublisher: only Trusted vouches for the name. - publisher: with a text value on a name nobody vouches for is unsure, with a reservation of its own beside "could not be read" and "ran out of time": publisher:microsoft leaves the entry out, !publisher:microsoft keeps it, and both say how many entries rest on such a name. any, none and ? stay certain, and an unsigned file is still a certain no. - The name carries "(not verified)" in the window's publisher cell, details panel and export, in bws show, and in the listing's signature cell. JSON and the snapshot file still carry the bare name. - Trusted is described as not checked for revocation where fields are described: the window's suggestions, the query language page and the README. - The query reservations of the command line move into Execution.QueryAdmissions so a test can hold them, and the window's into Sentences.Unjudged. Found while checking the above on a real file: the inspector asked WinVerifyTrust with WTD_SAFER_FLAG, documented by Microsoft only as "Not supported". With it a file whose bytes no longer match its embedded signature comes back as having no signature, so Tampered never arrived for such a file and it was reported as Not signed. The flag is gone. Verdicts over every entry on the machine this was built on are unchanged against the previous build, and an integration test changes one byte of a copy of the runtime's core library and expects Tampered. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security package SC: a publisher name is only taken at its word beside a Trusted signature, and a file changed after it was signed is reported as Tampered.
Publisher beside a verdict other than Trusted. The name is read back without walking the chain, so beside Tampered, Expired, UntrustedRoot or Unknown it is only what the certificate claims.
!publisher:microsoftused to leave out a Microsoft file changed after signing, with full confidence.BinarySignature.VouchesForPublisher- only Trusted vouches.publisher:with a text value on such a name is unsure, with its own reservation and sentence (window under the search box, command line on stderr):publisher:microsoftleaves the entry out,!publisher:microsoftkeeps it.any,noneand?stay certain. An unsigned file is still a certain no.bws showand in the listing's signature cell. JSON and the snapshot file are unchanged.Tampered never arrived for a file with its own signature. The inspector asked
WinVerifyTrustwithWTD_SAFER_FLAG, which Microsoft documents only as "Not supported". With it, a file whose bytes no longer match its embedded signature comes back as having no signature at all, so it was reported Not signed. Measured on copies of three signed files in a temporary folder:0x800B0100with the flag,0x80096010without. The flag is removed.No contract change: no JSON field, switch, exit code or snapshot schema.
Verification
TamperedSignatureTestsagainst realWinVerifyTrust).bws list --json --signaturesagainst the previous build on the machine it was built on: 801 of 801 entries identical, so no verdict on an unchanged file moved.🤖 Generated with Claude Code