How are signing key hashes a secure way to verify software?

My understanding of signing keys, when it comes to verifying open-source software, is that they’re used to prove authorship. But it seems like putting it in the software would give it away, and it can’t be used to hash the software itself, or the hash would change with every release. Couldn’t a malicious developer copy a piece of software, add malicious code, then provide the same key hash, which is often publicly known?

give what away?

they do change with every release

the private key used for signing would not be publicly known

I’ve gotten the impression that signing keys are very closely guarded secrets.

So is the signing key used to get the correct result when hashing the software, which only someone else with the key could get? If so, how can other apps verify software if they don’t have the key to do it?

The hash is publicly known.

I’ve decided to look up code signing to see how it works.

The private key (which is used for creating the signature) is kept private, yes

They use the public key to verify

Yes, but not the private key

Looking it up, this looks like something I just don’t know enough to understand.

You have a private key that you don’t share and a public key that you share. You use the private key to create a signature file for whatever you want someone else to be able to verify is coming from you.

The end user then needs to have your public key, your signature file and the data they want to verify. The public key is then used to verify that the signature file matches for the data you are verifying.

As long as you have the correct public key and the signers private key or system is not compromised, it guarantees it is coming from that individual/organization.

Then at least one of those things needs to be protected, right? Otherwise, someone could just copy all three.

no, only the private key needs to be kept secure

That’s the point. The signature, public key, and data are shared with anyone who needs it. Anyone who receives all three can then get a proof that the one who has the private key created the signature.

I see. So there’s no way to intrinsically check the authenticity of a piece of software. You need a database for what the values should be.

All you need to make sure is that the public key you use is in fact from the correct individual/organization when verifying something using a signature file.

Why don’t developers just give everyone the hash of the raw software, with no extra stuff? Any edited software will have a different hash. Whether it’s a public key or a raw file hash, you’re still trusting that the info you have came from the original author.

Since you now have to trust that this hash is coming from the correct developer every time you use it, instead of only having to do this once when getting their public key.

Shouldn’t this still be true of the scenario with the public key and signature file? Couldn’t someone take the code, the signature file, and the public key, edit the code, and then give the result of that hash? That seems like the same result with a few extra steps.

Without access to the private key the hash of code can’t be signed. So a person using the public key will be able to detect it was not from the someone with access to the private key.

A number of earlier responses did a good job of explaining. Rather than ask again in a slightly different way you may want to read up on public key encryption and how that is used to create digital signatures.

Here is a video that may help explain the concept to you if you would like

Many developer publish hashes of their releases.
Often in addition the the hash of the signing certificate

In layman terms, there are pair of keys that are used.
Private keys - are used to encrypt.
Public keys - are used to decrypt.
It’s mathematicaly done such way that you can’t have same signature using private and public keys. It’s impossible. So using public keys you can’t mimic author/developer and say you are real.
So, author, using private key and file hash is making signature file. That encrypt both author and mathematicaly enought strong signature that if you change even one bit in any of the publicly available files it will give error of missmatch.
If you download from developer site some file with his signature and download/make some shady public key or shady signing file it will say “missmatch”.
If you download some shady file but use oryginal author signature and public key it will missmatch.
All three parts must be from author unchanged to give positive result. And you can download signed file from anywhere, even from shady places, as long as it’s original copy it will atest that it’s original file.
And you can have author public key from author or from key library. If there is key in library signed to particular e-mail address you can’t register another one for it a long as first one is still valid.
It was established ages ago, in dinosaur era, by academic society for themselves as internet connections was failing all over and one need to have proof that file downloaded properly, or that diskette is not broken, or serial connection wasn’t disrupted.
We don’t use mathematics in hash from that era anymore as it was too weak. But principle stays, and infrastructure too.

Are you sure?
I think its the other way

Yes its the other way

public encrypts

private decrypts