who signed the binaries was irrelevant for this attack, because the issue was not checking any signature