Comment by maqp

4 years ago

Yeah you can actually just audit the self-extracting code, and create detatched signature for it for every instance.

But yeah my bad, apparently the actual problems with this tools are with usage, password hashing, and non-existent secret sharing mechanisms.