Security Now (Audio) SN 1065: Attestation - Code Signing Gets Tough
39 snips
Feb 18, 2026 They dig into a massive spyware and Chrome extension surveillance campaign that exposed millions of users. Code signing and attestation changes get close scrutiny as the hosts recount navigating new lawyer/notary requirements. Windows, Chrome 145 device-bound credentials, and a WinRAR zero-day are discussed. A leaked Graphite tool and the first malicious Outlook add-in raise fresh alarm about software supply-chain trust.
AI Snips
Chapters
Books
Transcript
Episode notes
Prioritize Page Efficiency Over Heavy CMS
- Design web systems for CPU efficiency; dynamic CMS pages can overwhelm servers during traffic spikes.
- Consider static generation or caching to avoid costly scaling and DDoS-like failures.
Device-Bound Session Credentials Arrive
- Chrome 145 adds device-bound session credentials that bind session cookies to a device's secure enclave.
- This prevents stolen session cookies from being reused elsewhere, boosting cookie authentication integrity.
Device Compromise Bypasses End-To-End Crypto
- Mobile spyware like Paragon's Graphite can exfiltrate decrypted IM content by operating inside the compromised device.
- End-to-end encryption protects only in transit; device compromise defeats it.



