How PluggedDesk trusts an update
An updater is the one part of an application that is allowed to replace all the others. This is how ours decides what it will run, and what it refuses.
An updater is the one part of an application that is allowed to replace all the others. Whoever can feed it a file can run code on every computer the application is installed on. For a tool that holds the way into servers, that is the question that matters most, so it is the one we answered first.
The rule
PluggedDesk installs a release when a key compiled into PluggedDesk has signed it. Nothing else counts: not where the file came from, not the certificate of the server that served it, not the account that uploaded it.
We wrote it that way round on purpose. "The file came from our server over HTTPS" is a statement about a server. Servers are replaced, misconfigured, mirrored and, sometimes, broken into. "The file was signed by the release key" is a statement about the file.
What is signed
Each release has a small manifest. It names the version, the channel, the platform, and one installer: its file name, its size in bytes and its SHA-256.
The manifest is signed with ECDSA on the P-256 curve, over its exact bytes. The signature travels beside it, in a file of its own. PluggedDesk carries the public half of the key.
The installer is not signed by this key directly, and does not need to be: the manifest pins it. A different installer has a different hash, and a manifest with a different hash has a different signature.
What PluggedDesk checks, in order
- The signature, against the keys it was compiled with. A signature that names another algorithm, or a key PluggedDesk does not carry, is refused before any arithmetic is done.
- The manifest, strictly. An unknown version of the format, a missing field or a field of the wrong kind refuses the whole file. It does not guess.
- That the release is for this installation: this product, this channel, this platform.
- That the version is strictly newer. This one is easy to miss. Every old release has a genuine signature. Without this check, anybody who kept a copy of an old manifest could offer it again and take an installation back to a version with a known fault.
- Then, and only when you have agreed, it downloads the installer and checks its size and SHA-256 against the manifest. A file that does not match is deleted.
- It holds the file open from that check until the installer has started, so that nothing can swap it in between.
What the website cannot do
The website you are reading serves the update channel. It holds no key that can sign a release.
It goes further: it refuses to publish a release that is not signed by the release key, and it checks the installer against the manifest before it accepts either. Uploading needs a credential. But a stolen credential can upload only what the release key has already signed, which is to say, a release.
We test this the blunt way: we take each of these rules out of the code, one at a time, and run the tests. If the tests still pass, the rule was not being tested, and we fix the tests.
What this does not protect against
A compromised release key. If the key is stolen, whatever it signs will be accepted by every installation that trusts it, until those installations are updated to a version that does not. That is why the key is kept apart from the website, why PluggedDesk can carry more than one key (so that a key can be replaced in an orderly way), and why a withdrawn key is removed from the application rather than marked as bad somewhere online.
And it does not replace a publisher certificate. The installer you download by hand is not yet signed in the way Windows looks for, so Windows will tell you that the publisher is unknown. Until that changes, check the download yourself: it takes ten seconds.