Earlier quoted context omitted.
I agree with you that they are not necessarily removing developers from other projects to work on licensing. However, a percentage of code in Windows is dedicated to validating licensing and preventing piracy. > In fact, there is no company or software community anywhere that writes highly complex and bug free software. It's not possible. I agree with this point. For this reason, the point I'm trying to make is that…
But having updates cryptographically signed and checked against a list of (presumably) trusted certificates is in my best interest. The "bug" here was in key management, not in SW that's running in my computer.
The code that caused the certificate chain to be compromised is related to licensing Terminal Services on Windows Server. That is how their key management failed, and that is what I'm railing against--The fact that this ability to sign binaries with a legitimate Microsoft certificate has been hidden away in copies of Windows Server for years by mistake. And not for any direct customer benefit, but to employ a licensing scheme.