I remember the good old days when people were actually trusted to do their own research before downloading a potentially dangerous exe. Now all we have are app store and certificate rackets. Im looking at Google and Apple too. Shame on the industry for accepting 30% revenue share on their services. The idea of an app store is great but not when it excludes other legitimate ways of installing software on device. These…
Notepad++ drops code signing for its releases
71–80 of 335 posts
Re: Notepad++ drops code signing for its releases
#72> I realize that code signing certificate is just an overpriced masturbating toy of FOSS authors. I'm not sure what the author means by this.
The author is saying that signing certificates are something that FOSS authors enjoy using, but they have no practical purpose outside of that enjoyment.
Re: Notepad++ drops code signing for its releases
#73Re: Notepad++ drops code signing for its releases
#74I remember the good old days when people were actually trusted to do their own research before downloading a potentially dangerous exe. Now all we have are app store and certificate rackets. Im looking at Google and Apple too. Shame on the industry for accepting 30% revenue share on their services. The idea of an app store is great but not when it excludes other legitimate ways of installing software on device. These…
"the good old days", as in, "the days when the average person had no freaking clue if something was safe, but installed it anyway because it's completely unreasonable to expect them to do otherwise"? If your security model is "do your research" then you're going to fail.
Re: Notepad++ drops code signing for its releases
#75Windows signing is a ripoff, $500/year you're getting nothing. Your certificate is not trusted. You have to "get reputation for it" before Windows Defender would stop giving users warnings. Also, renewing certificate is not a thing. Every time you have to get a new one, with same story of "reputation" again. [1] https://www.digicert.com/order/order-1.php
Reputation requirements either shouldn't have backdoors or shouldn't exist in the first place.
1. https://twitter.com/JosephRyanRies/status/951643158118567937
Re: Notepad++ drops code signing for its releases
#76Earlier quoted context omitted.
"It's $828 per year" for ... a cert? What makes code signing this expensive?
Greed, mostly. Digicert lists EV code signing certs as $664/yr. But if you are to enter their site through a side door or just plainly cry into the support's jacket, then the price magically drops to $104/yr. And that's for an EV cert! So the only reason there are $600 certs is that there are people who do pay that.
Re: Notepad++ drops code signing for its releases
#77Earlier quoted context omitted.
Every good dev knows to stay the hell away from sourceforge!
Only if that's part of your definition of a good dev. I know plenty of good devs who downloaded software from Sourceforge back when it was big. Let me guess: you also dislike GitHub because it's closed, and wish people would distribute software from their own, self-hosted git repositories?
Sourceforge is a hostile source of malware : https://mail.gnome.org/archives/gimp-developer-list/2015-May...
You mock those who desire freedom at your own risk. Github is microsoft now, and supporting it feeds the beast.
Re: Notepad++ drops code signing for its releases
#78Earlier quoted context omitted.
>I kind of see them like taxi medallions Taxi medallions are pricey because there's limited supply and high demand. Code signing certificates have limited demand and unlimited supply, but are expensive because they require manual verification (like EV certificates) and has a bunch of startup costs (to get included as a root).
Factors keep both items expensive, and both are effectively required for doing certain types of business.
Re: Notepad++ drops code signing for its releases
#79Orthogonally, I also think that $99 App Store fees are a terrible waste of money. You should get charged only when submitting to an app store for review.
There are plenty of root certificates that came installed on my computer, and I don't even trust them. Why would these CAs charge so much for so little value?
Re: Notepad++ drops code signing for its releases
#80Earlier quoted context omitted.
Only if that's part of your definition of a good dev. I know plenty of good devs who downloaded software from Sourceforge back when it was big. Let me guess: you also dislike GitHub because it's closed, and wish people would distribute software from their own, self-hosted git repositories?
Devs get better by learning from mistakes. Sourceforge is a hostile source of malware : https://mail.gnome.org/archives/gimp-developer-list/2015-May... You mock those who desire freedom at your own risk. Github is microsoft now, and supporting it feeds the beast.