Since their only known benefit was issuing certificates in support of a quite-possibly-shady email system, I'm comfortable with saying that the cost-benefit analysis comes down firmly against TrustCor.
Since their only known benefit was issuing certificates in support of a quite-possibly-shady email system, I'm comfortable with saying that the cost-benefit analysis comes down firmly against TrustCor.
Can somebody explain the significance of the malware being unobfuscated, and why that's apparently more concerning than if it had been obfuscated?
In other words: it suggests that the CA and the malware creator are one and the same, which was then further substantiated by their shared executives, addresses, etc.
This suggests that the relationship between MsgSafe and Measurement Systems was not a typical "oops, we added a library that turned out to be malware" relationship. Instead, they seem to have had access to the raw source code, rather than the packaged binaries, which in conjunction with other evidence indicates a close degree of collaboration between the malware developers and MsgSafe. It's not a smoking gun, but it's enough to warrant distrust.
Rachel’s suggestion in the thread is that the other examples of this SDK that have been observed obfuscated are much more recent, and that perhaps obfuscation was something the company has started doing more recently.