Stuxnet's rootkit drivers carried valid digital signatures from stolen certificates. Which defensive lesson follows?
- A.A valid signature proves who signed a file yet not their intent
- B.Signed code is certified free of malicious logic by the signer
- C.Certificate theft is impossible for large hardware vendors
- D.Driver signing ended with the older Windows versions
Why A is correct
A signature shows the holder of a private key signed the code, so a stolen key lets malware look trusted. Signed files can still be harmful, vendors do lose keys, and driver signing was in force when Stuxnet appeared.
Know someone studying for OT Security Fundamentals? Send them this one.