[A83] Re: TI-Cares


[Prev][Next][Index][Thread]

[A83] Re: TI-Cares




> Van: Dan Englender <dan@calc.org>
>
> (Warning/Disclaimer: You've caught me in a bad mood.)
>
> Sorry, but I think *you* miss something...
>     From TI's standpoint, the vital security piece in their signing
scheme
> is the private key.  TI has released the private key and by doing this
has,
> in effect, given up all control on Flash Apps.
> 
> > Now I've read your mail some better I've seen that it also could be
that
> > you ment to say that Ti wouldn't loose money on releasing the rabsign
> > source-code... That would be true, because you should know the other
> > (private/open) keys used by the TIOS (Cerberus...), before being able
to
> > generate your own keys. But if we would have the encoder source, then
it
> > wouldn't need that much effort to find new keys that could also 'fit',
off
> > coarse, I think Ti will still keep it for themselves for some time,
utill
> > then... (What is the economic lifespan of the Ti83+?)
> .......You talk about how with the rabsig source you could create your
own
> keys (whether or not you could do this is a different story, with an
answer
> probably of no, as Peter pointed out), but the point is, why would you
want
> to do this, and why would TI care?  The freeware key is "the key".  You
can
> sign anything with it.  If TI was worried about the "economic lifespan"
of
> the TI-83 Plus they wouldn't have released the freeware key.  I don't
even
> understand what you're trying to say.  TI is not going to be making *any*
> money on your applications, you don't need any other keys.

Erm, sorry but I thought there was some difference between the freeware
(also called shareware) key and the signings you had to pay for, that there
was also something with calc-IDs etc.

So companies could let Ti sign their programs and in that way control who
(..which calc..) could run the programs... Some sort of
shareware-registration I mean...

Why would Ti call it shareware-key if they didn't had some idea of selling
commercial signings after releasing the key?

I hadn't even expect Ti to give up control over their commercial
appsigning, so I didn't think of something like this.

	Henk Poley