Hardware, platform and safety / Security and privacy
Where does “Signed files” fit in Simca, with a focus on key ceremony not done?
Built in the repository (checked files or tested library code; not a product you can run yet) C0192
Everything the launcher installs is signed: packages, update manifests, entitlements, the catalog snapshot and price documents. A missing signature or an empty checksum is an error, never skipped. Ed25519 is used in the packaging code with test keys only; no production key exists in the repository and the key ceremony is not done. A revocation list and a trusted key set exist as code. Plan for: key ceremony not done; key loss; revocation travels with launcher updates. It exists only as a file in the repository, not as a product feature.
How to read this
The tag above says how real the answer is. Answers describe the plan in the repository and design documents. No app is released. Where an answer touches tax or law, treat it as a theme to verify with a qualified local adviser.
More in Security and privacy
- Is “Device pairing” supported today, in particular regarding unknown device?
- What goes wrong with “Data minimisation” in a shop, especially around customer id thresholds?
- Where does “PINs and sessions” fit in Simca, in particular regarding shoulder surfing?
- See it in context with the whole topic
- Search all answers