On Dec 7, 2011, at 1:56 PM, Peter Gutmann wrote:

> Steven Bellovin <smb at cs.columbia.edu> writes:
>> Assume that there is some benefit to digitally-signed code.
> There is at least one very obvious benefit: When malware is signed, it can't
> mutate on each generation any more but has to remain static.  This makes it
> easier for the anti-malware folks to detect.

This is only true if signing the malware is an expensive (in some terms) proposition.
It's certainly not expensive in terms of computing power.

