Hi,
The idea behind AppLocker seems to be good. What I like the most is Publisher Based rules. However let's say I create a rule that says:
"Allow all files digitally signed by Microsoft"
What prevents someone from spoofing a signature? Can someone get a signing tool and sign their malware as if they were Microsoft? or how does Microsoft prevent the Publisher Rules feature from being a huge security hole?
Can someone please explain?
Regards,
Dave