"Criminals have been faking Microsoft's code signatures for several years"

Faking as in signing with Microsoft's keys or faking as in throwing together a self-signed certificate in the name of "Microsoft". I think the former would be og considerable interest to the cryptographic community whereas the latter ... just doesn't count.

