How Quikap trusts an update
An updater is the one part of a program that is allowed to replace all the others. This is how ours decides what it will run, and what it refuses, before a single release exists.
An updater is the one part of a program that is allowed to replace all the others. Whoever can feed it a file can run code on every computer the program is installed on. For a tool that sees everything on your screen, that is the question that matters most, so it is the one we answered first, before either program can capture anything.
The rule
Quikap and QuikapStudio install a release when a key compiled into them has signed it. Nothing else counts: not where the file came from, not the certificate of the server that served it, not the account that uploaded it.
We wrote it that way round on purpose. "The file came from our server over HTTPS" is a statement about a server. Servers are replaced, misconfigured, mirrored and, sometimes, broken into. "The file was signed by the release key" is a statement about the file.
What is signed
Each release has a small manifest. It names the product (there are two: the capture utility and the editor), the version, the channel, the platform, and one installer: its file name, its size in bytes and its SHA-256.
The manifest is signed with ECDSA on the P-256 curve, over its exact bytes. The signature travels beside it, in a file of its own. Both programs carry the public half of the key.
The installer is not signed by this key directly, and does not need to be: the manifest pins it. A different installer has a different hash, and a manifest with a different hash has a different signature.
What a program checks, in order
- The signature, against the keys it was compiled with. A signature that names another algorithm, or a key the program does not carry, is refused before any arithmetic is done.
- The manifest, strictly. An unknown version of the format, a missing field or a field of the wrong kind refuses the whole file. It does not guess.
- That the release is for this installation: this product, this channel, this platform. The editor never installs the capture utility's release, however genuine, and the other way round.
- That the version is strictly newer. This one is easy to miss. Every old release has a genuine signature. Without this check, anybody who kept a copy of an old manifest could offer it again and take an installation back to a version with a known fault.
- Then, and only when you have agreed, it downloads the installer and checks its size and SHA-256 against the manifest. A file that does not match is deleted.
- It holds the file open from that check until the installer has started, so that nothing can swap it in between.
Two programs, one key, one verifier twice
The capture utility is written in Rust and the editor in C#. That is two implementations of the same rules, and two implementations drift unless something stops them. What stops them is a fixture: a manifest signed with the real release key, kept with the tests of both programs. Each verifier must accept it, byte for byte, and must refuse the forgeries the tests make from it. If one implementation changes what it accepts, the other's tests say so.
What the website cannot do
The website you are reading serves the update channels. It holds no key that can sign a release.
It goes further: it refuses to publish a release that is not signed by the release key, and it checks the installer against the manifest before it accepts either. Uploading needs a credential. But a stolen credential can upload only what the release key has already signed, which is to say, a release.
What this does not protect against
A compromised release key. If the key is stolen, whatever it signs will be accepted by every installation that trusts it, until those installations are updated to a version that does not. That is why the key is kept apart from the website, why the programs can carry more than one key (so that a key can be replaced in an orderly way), and why a withdrawn key is removed from the programs rather than marked as bad somewhere online.
And it does not replace a publisher certificate. An installer you download by hand will not yet be signed in the way Windows looks for, so Windows will tell you that the publisher is unknown. Until that changes, check the download yourself: it takes ten seconds.