Oh, for fuck's sake. (Pretty cool though.)
Conversation
It's not a bypass for signature verification. There's older hardware with vulnerabilities in the signature verification but this is not itself a bypass of a real security feature. It will help people to make use of those kinds of security vulnerabilities though.
This kind of encryption is not much of a security feature. It's obfuscation that's inherently possible to bypass by extracting the decryption key from hardware. Apple does it too. I think it's quite misguided and ends up reflecting poorly on these companies when it's bypassed.
1
1
Depending on source code not being leaked and keys not being extracted from hardware as barriers to exploitation is concerning. They should welcome security research and make it easier rather than putting up obstacles. Focus on actually making it secure not hard to research it.
2


