Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Cracking the code to build trust in business applications

by The Gurus
August 7, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

Cracking the code to build trust in business applications

John Grimm, Senior Director, Thales e-Security
Establishing trust in an increasingly connected and virtualised world is something businesses strive to achieve as they increasingly depend on digital services to complete daily tasks. Cloud-based platforms and mobile computing have certainly proven popular with businesses in improving efficiency and driving down operational costs. However, the more these technologies are used, along with the arrival of the ‘app store economy’, the more business logic resides and is executed on insecure devices. This has created a challenge for anyone developing code that will run in distributed locations as they need to ensure that their software has the ability and proper protections to run in environments which they can have little control over.
In light of this challenge, Facebook announced that from October 2015, application developers will be required to move from SHA-1 to a more secure type of hashing algorithm, SHA-2, in support of digital signatures for their apps. This is definitely the right move, especially when SHA-1 has been considered too weak for proper security measures for a while, and thus makes computers vulnerable to potential hash collision attacks. But as application developers move in this direction, it is important that they do not lose sight of, or overlook the value of, signing keys when developing code.
Read the signs
Although signing keys don’t encrypt data (like encryption keys do), signing key security is the backbone of code signing technology. It is an essential tool to verify the source of software and is essential in providing proof that it has not been intercepted or altered since its publication.
Digital signatures go beyond electronic versions of traditional signatures by invoking cryptographic techniques to dramatically increase security and transparency. However, simply requiring code to be signed does not ensure security. An essential element of increasing the assurance level of a code signing process is strong protection of the private signing key. If a code signing key is lost or stolen, an attacker may be able to sign a malicious upgrade that either steals valuable and sensitive information or renders numerous devices inoperable. Furthermore, if a private key becomes known to anyone besides the authorised individual, they will be able to create digital signatures that will be seen as ‘valid’ when verified using the associated public key. It will even appear to come from the organisation identified in the associated digital certificate.
Navigating through the threat landscape 
Today, businesses are faced with navigating their way through an ever more challenging threat landscape as the levels of malware continue to rise and the types of attack evolve. Business applications running on host servers are increasingly vulnerable to advanced persistent threats (APTs), introduced through malware, as well as insider attacks and hacking.
APTs are an issue for businesses as attackers can change application code or device firmware while acting in a way so as to avoid timely detection. The threats are significant and don’t necessarily involve just corporate data theft, but extend to malware on critical national infrastructure such as a flight computer in a plane, smart grids or even traffic lights. This makes the loss of a code signing key potentially catastrophic.
Such threats are putting more pressure on security professionals to increase the security assurance level of their code signing practices. Application code is an appealing target for attackers, as it opens the doors to a company’s high value data. Given that application-level attacks can be extremely hard to detect, organisations are at risk of finding themselves in the grip of long-term breaches and high volumes of data theft.
Overcoming the challenges
Despite the acknowledged threat of lost or stolen code signing keys, businesses have to deal with a number of factors that can make them challenging to protect.
The first is that signing keys are typically held on developer workstations, where developers optimize their environment for code writing and not system security. However, this is risky practise with attackers at large.
In addition, the need for centralised code signing approval processes can be challenging for large software organisations, where the volume and distribution of software build stations requires shared resources.
The solution to these key management headaches is to protect keys in a dedicated key management device called a Hardware Security Module (HSM). As well as providing a dedicated, certified environment to protect private digital signing keys, HSMs perform the code signing operations and provide three aspects of protection to ensure that the process remains effective:

  • Simplification of the key backup to ensure the keys don’t get lost
  • Provision of independently certified life cycle protection against accidental or malicious key theft
  • Customisable controls over code signing procedures including dual control and multifactor authentication against unauthorised use of the code signing keys.

Although hardware-based security may sound like an odd choice to solving software and cloud-based vulnerabilities, it’s important to remember that all virtualised workloads are deployed on a hardware platform at one point in time. Dedicated hardware protection is a time honoured best practice.
Security threats are evolving in line with new technologies and this is leaving us open to ‘gaps’ or vulnerabilities that you can be sure attackers will be quick to exploit. It has never been so important for us to be able to trust the infrastructure that supports our reliance on automation. Code signing processes, private code signing keys, and digital certificates are of critical importance in a digital world. Organisations need to protect their systems and the people that implement and control them in order to not only guard their software, but also their brand reputation.

ShareTweet
Previous Post

US Government hacked AGAIN, is Russia to blame?

Next Post

Hacking airport security systems with a common laptop

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol