Author Topic: Are program updates digitally signed?  (Read 4825 times)

0 Members and 1 Guest are viewing this topic.

Chankama

  • Guest
Are program updates digitally signed?
« on: November 21, 2005, 09:30:10 PM »
Hey guys. These days I am getting a message from Avast! saying that a program update is available. My question is, are the "Program updates" digitally signed?

I asked a similar question regarding the "Virus definitions" a few weeks ago before downloading Avast!, and I was told that they virus definition updates ARE digitally signed.

However, I think the program update is even more critical. We don't want any "malicious" program updates from taking place. Thanks.

-Chankama

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Are program updates digitally signed?
« Reply #1 on: November 22, 2005, 01:29:14 AM »
This topic has been recently covered so a forum search should be able to track it down.

I can't remember the official position as to whether they are explicitly signed but there are checks in force to ensure they are what they appear to be.

This is the thread that you started on the same topic on October 11 - http://forum.avast.com/index.php?topic=16868.0 So I guess that program updates fall into the same category.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Are program updates digitally signed?
« Reply #2 on: November 22, 2005, 01:33:21 AM »
Are the "Program updates" digitally signed?
Yes, they are as the same as the virus databases.
The best things in life are free.

Chankama

  • Guest
Re: Are program updates digitally signed?
« Reply #3 on: November 22, 2005, 02:08:45 AM »
Thx Tech. Any further info on the type of signature that is performed? I am presuming it uses the same public key as for the virus def. updates.

This topic has been recently covered so a forum search should be able to track it down.

I can't remember the official position as to whether they are explicitly signed but there are checks in force to ensure they are what they appear to be.

This is the thread that you started on the same topic on October 11 - http://forum.avast.com/index.php?topic=16868.0 So I guess that program updates fall into the same category.

Hey David. Actually they do "not" fall into the same category. Having malicious definitions, in the worst case, will corrupt your detection database and prevent things from being detected  or detect/remove things that shouldn't be removed. Where as, malicious program updates can do much more damage IMO.

The update procedure in avast! seems to be different for the def. updates and the program updates as you can actually specify whether they should be done automatically or not. So, the update logic for the 2 types of updates diverge at least in some areas. I wanted to make sure whether they diverge in the digital signatures as well.

A [forum search] about "digitally signed" only brings up my old query about virus definition signatures as well as this thread:
http://forum.avast.com/index.php?topic=12275.msg103940#msg103940

This thread doesn't answer my question explicitly.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Are program updates digitally signed?
« Reply #4 on: November 22, 2005, 02:16:46 AM »
Tech. Any further info on the type of signature that is performed?
I've asked for superior help... the programmers should say something more upon my guesses  ;D 8)
The best things in life are free.

kubecj

  • Guest
Re: Are program updates digitally signed?
« Reply #5 on: November 22, 2005, 02:25:47 AM »
Every file coming from the update servers is digitally signed with 1024 bit key. In fact, the difference between program and database update is minimal from the updater's point of view.

Chankama

  • Guest
Re: Are program updates digitally signed?
« Reply #6 on: November 22, 2005, 05:48:08 AM »
Thx kubecj and Tech. Appreciate your quick response. 1024-bit? So I guess it's a RSA signature. I was worried about updating the program, but now I guess I shouldn't worry. :)

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Are program updates digitally signed?
« Reply #7 on: November 22, 2005, 09:59:29 AM »
I also thing it would be a little hard to modify signatures/program updates by 3rd party without seriously breaking avast!'s operations and way how it works.
You'd have to completely reverse engineer it and that probably isn't exactly an easy task...
Visit my webpage Angry Sheep Blog

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Are program updates digitally signed?
« Reply #8 on: November 22, 2005, 04:39:13 PM »
Thx Tech. Any further info on the type of signature that is performed? I am presuming it uses the same public key as for the virus def. updates.

This topic has been recently covered so a forum search should be able to track it down.

I can't remember the official position as to whether they are explicitly signed but there are checks in force to ensure they are what they appear to be.

This is the thread that you started on the same topic on October 11 - http://forum.avast.com/index.php?topic=16868.0 So I guess that program updates fall into the same category.

Hey David. Actually they do "not" fall into the same category. Having malicious definitions, in the worst case, will corrupt your detection database and prevent things from being detected  or detect/remove things that shouldn't be removed. Where as, malicious program updates can do much more damage IMO.
By falling into the same category, I meant that if VPS updates are digitally signed it would follow that Program updates would be digitally signed, as it has now been confirmed.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security