Live data from Hacker News

Notepad++ drops code signing for its releases

notepad-plus-plus.org

131–140 of 335 posts

Re: Notepad++ drops code signing for its releases

#131
Anyone have any source that cites it's sources for the profit margins on code signing rackets. I imagine for mobile the margins are especially high since phone o/s design makes it much easier to put less effort into audits. I bet the profits margins in both mobile and standard are absolutely monsterous. By the principals of business I assume they put in the least amount of effort possible while still putting in enough to protect themselves from blame

Re: Notepad++ drops code signing for its releases

#132
post #114

Earlier quoted context omitted.

> Funny thing about trust: I trust a developer who drops some $$$ on a code-signing certificate more than I trust a developer who doesn't. Even if it's just $20. Why? If I expect to make four figures on spreading malware/adware, and I can assuage the nerves of people like you by spending two or three figures on a certificate, I'm going to buy the certificate and make it look all nice and pretty and take your money. >…

I would imagine barrier to entry plays a large role in the sense of comfort here. If you have to incorporate in Delaware and pay $500 and jump through hoops, you’re more likely to turn to a simpler and easier alternative.

Exactly! I trust "you must do some things to obtain this" more than I trust "you don't have to do anything".

Re: Notepad++ drops code signing for its releases

#133
post #110

Earlier quoted context omitted.

> Even if it's just $20. $20 doesn't get you an EV certificate anywhere. We're talking about non-trivial hundreds of dollars per year, which is completely unsustainable for an open source driver for example.

My point was I would trust someone who drops $20 more than I would trust someone who drops nothing. $61/yr (USD) will get you an OV cert - there are 10% discount codes that are easy to find for these guys, and their list price is $67/yr: https://codesigning.ksoftware.net/ But the Notepad++ guy will need a business registered with that name before he can obtain CN=Notepad++, no matter how much he's willing to pay.

This certificate doesn't help to bypass UAC and "unsecure" prompt still be shown to the user.

Re: Notepad++ drops code signing for its releases

#134

> I realize that code signing certificate is just an overpriced masturbating toy of FOSS authors. I'm not sure what the author means by this.

Yeah, if this is about Windows UAC and cert/app naming problems, how is that related to FOSS whatsoever? Seems like a whiney rant that shouldn't have been made public.

Re: Notepad++ drops code signing for its releases

#135
post #98
post #86

Earlier quoted context omitted.

You can get a certificate far cheaper than that - K-Software offer them for $85/year. I've used them for years and can recommend them.

K-Software does not sell EV certificates for $85/yr. They start at $349/yr. The parent comment's issue is that EV certificates are essentially required due to the poorly-designed SmartScreen reputation filter. The $85/yr certificate you're mentioning doesn't help solve this.

I didn't know about the EV workaround and the OP didn't mention it.

I've never used an EV cert before for code signing. When we first started, I think Smartscreen was a nuisance for about 2 weeks, but years on, and I've never had to think about it again. Even when we've renewed the cert.

Re: Notepad++ drops code signing for its releases

#136
post #114

Earlier quoted context omitted.

> Funny thing about trust: I trust a developer who drops some $$$ on a code-signing certificate more than I trust a developer who doesn't. Even if it's just $20. Why? If I expect to make four figures on spreading malware/adware, and I can assuage the nerves of people like you by spending two or three figures on a certificate, I'm going to buy the certificate and make it look all nice and pretty and take your money. >…

They didn't say they trust the developer who spends the money absolutely , they said they trust the developer who spends the money more than they trust one who doesn't. Which is fair -- as you note, not every scammer will be scared off by the need to spend some money to pull the scam off; but some will, so the ratio of legitimate developers to illegitimate ones will be higher in markets where there's some cost to ent…

> not every scammer will be scared off by the need to spend some money to pull the scam off; but some will

The same goes for developers, as you can see in this article.

Re: Notepad++ drops code signing for its releases

#137
post #114

Earlier quoted context omitted.

> Funny thing about trust: I trust a developer who drops some $$$ on a code-signing certificate more than I trust a developer who doesn't. Even if it's just $20. Why? If I expect to make four figures on spreading malware/adware, and I can assuage the nerves of people like you by spending two or three figures on a certificate, I'm going to buy the certificate and make it look all nice and pretty and take your money. >…

They didn't say they trust the developer who spends the money absolutely , they said they trust the developer who spends the money more than they trust one who doesn't. Which is fair -- as you note, not every scammer will be scared off by the need to spend some money to pull the scam off; but some will, so the ratio of legitimate developers to illegitimate ones will be higher in markets where there's some cost to ent…

> Which is fair -- as you note, not every scammer will be scared off by the need to spend some money to pull the scam off; but some will, so the ratio of legitimate developers to illegitimate ones will be higher in markets where there's some cost to entry.

The big scammers, the ones who are the most likely to have an actual business plan for selling my information, aren't.

Note that I know Adobe is "trusted" in the relevant sense.

Note that I don't think Adobe is trustworthy in any real sense.

Re: Notepad++ drops code signing for its releases

#138
post #25

Earlier quoted context omitted.

>I remember the good old days when people were actually trusted to do their own research before downloading a potentially dangerous exe. Is there any evidence that was ever really a thing / effective? How could you possibly know? There are plenty of examples of previously trustworthy software becoming untrustworthy, same with sites you download the code from. That line reads like the absurd advice that security exper…

Back in the day, you used to evaluate trust by making smarter decisions about how you went about installing things. You downloaded it to an isolated environment and ran it and proved it didn't cause unexpected side effects. It was run behind a firewall that could log internet communication. If it proved to be good, you ran it in your main environment. If it proved to be bad you warned everyone who would listen to you…

”and proved it didn't cause unexpected side effects.”

and convinced yourself it didn't cause unexpected side effects.

Put a one month timer in your malware, and this would get past many of such attempts to ‘prove’ the software isn’t evil.

Add a few countermeasures against clock shifts (e.g. only be active a few minutes each month or only activate when a) enough time and b) enough user interactions have passed from the first run), and you’ll effectively get past most, if not all, of such black-box testing exercises.

Re: Notepad++ drops code signing for its releases

#139
post #70

Windows signing is a ripoff, $500/year you're getting nothing. Your certificate is not trusted. You have to "get reputation for it" before Windows Defender would stop giving users warnings. Also, renewing certificate is not a thing. Every time you have to get a new one, with same story of "reputation" again. [1] https://www.digicert.com/order/order-1.php

Wait are you saying that Apple Developer program for 99$/year is actually quite a good deal in comparison?

I will definitely pull this thread out next time someone complain that Apple is too expensive and that they are milking the poor developers...

Re: Notepad++ drops code signing for its releases

#140
post #17

I remember the good old days when people were actually trusted to do their own research before downloading a potentially dangerous exe. Now all we have are app store and certificate rackets. Im looking at Google and Apple too. Shame on the industry for accepting 30% revenue share on their services. The idea of an app store is great but not when it excludes other legitimate ways of installing software on device. These…

Those days never existed. Which is why certs, app stores, and walled gardens exist.
Post reply on HN