Posted November 28, 2023
gog still only using sha-1 to digitally sign files. still okay, crypto security wise, but not for long. (yes, i read white papers and some new moves are happening that are going to be public with tools)
even loner devs (some) now double up and use both sha-1 and sha-256 to sign files.
win 12 will require it anyway, so soon enough they will be forced to add it but still, they should start using it now.
finally, many old games/files (many still sold, so not just those old removed ones) are not even signed. ok, they were released here before digital signatures were truly a thing, but hey, you know, you can sign them anytime.
to the armchair "generals". yes, it's free to add/use different crypto methods and it costs no extra.
the old games that are not signed will soon enough (win12 or maybe 13 if outcry and M$ backs off some) not be installable (or even usable) under future windows versions, so major problem indeed.
IT'S TIME!!!
1.) Start also using SHA-256 to signed files,
2.) Sign old games that were and still are not digitally signed!!!
3.) Add integrity checks to installers that don't have them.
even loner devs (some) now double up and use both sha-1 and sha-256 to sign files.
win 12 will require it anyway, so soon enough they will be forced to add it but still, they should start using it now.
finally, many old games/files (many still sold, so not just those old removed ones) are not even signed. ok, they were released here before digital signatures were truly a thing, but hey, you know, you can sign them anytime.
to the armchair "generals". yes, it's free to add/use different crypto methods and it costs no extra.
the old games that are not signed will soon enough (win12 or maybe 13 if outcry and M$ backs off some) not be installable (or even usable) under future windows versions, so major problem indeed.
IT'S TIME!!!
1.) Start also using SHA-256 to signed files,
2.) Sign old games that were and still are not digitally signed!!!
3.) Add integrity checks to installers that don't have them.
Post edited November 29, 2023 by GOGer