# digital signatures

Digital signatures are cryptographic transformations or asymmetric-key operations used to authenticate a signatory or data origin, protect data integrity, and support non-repudiation.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## The Asset Trap

DevFeed: [The Asset Trap](<https://devfeed.tech/articles/the-asset-trap-36999.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-asset-trap/>)

Author: Adam

Published: 2020-12-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [solarwinds](<https://devfeed.tech/topics/solarwinds.md>), [digital signatures](<https://devfeed.tech/topics/digital-signatures.md>), [email](<https://devfeed.tech/topics/email.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [email](<https://devfeed.tech/tags/email.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

This commentary uses the SolarWinds attack to explain an asset-focused threat-modeling trap. It argues that defenders should consider assets attackers want, such as DKIM keys, which can be used to forge emails that pass validity checks, and recommends rotating those keys regularly.

### Source excerpt

As we look at what's happened with the Russian attack on the US government and others via Solarwinds, I want to shine a spotlight on a lesson we can apply to threat modeling.