Live data from Hacker News

Notepad++ drops code signing for its releases

notepad-plus-plus.org

191–200 of 335 posts

Re: Notepad++ drops code signing for its releases

#191
post #169

Earlier quoted context omitted.

Your trust is misplaced; a developer who drops $$$ on a certificate could be a dyed-in-the-wool criminal. Just because code is signed and certified doesn't mean it doesn't do anything bad. Signing and certificates revolve around trust/mistrust in the delivery channel not in the purveyor. That problem can be solved with other tools, like PGP. You don't have to be blackmailed by a platform's certificate racket.

> That problem can be solved with other tools, like PGP. You don't have to be blackmailed by a platform's certificate racket. It kind of works that way in Linux world where artifacts are PGP signed and to get your key into distro store one has to have "reputation". With the caveat that different distros have different schemes. X.509 used by Windows has two nice properties that PGP doesn't - certificate attestation (M…

Kinda. You can use mimikatz to override the checks that the private key is isolated, you can even override 'no export' flag. Timestamping relies on external trusted timestamp providers implementing RFC 3161. There are many out there, maybe you could get a false timestamp out of them. I agree could be stronger than PGP, however it suffers a design flaw in that it considers the geometry of the PE file. PGP signs the whole blob. CVE-2017-0215 is an example of bypass by copying a previously signed header. It is more fragile and has been bypassed historically.

Re: Notepad++ drops code signing for its releases

#192
Does this mean that some users won't be allowed to install Notepad++ because it's not signed? I know some corporate environments have restrictions on downloaded installers.

Off topic, but I have to say that whenever I need to open hundreds of files at once and perform regex operations-- this editor rocks that task like no other. Kudos to Notepad++

Re: Notepad++ drops code signing for its releases

#193
post #114

Earlier quoted context omitted.

> Funny thing about trust: I trust a developer who drops some $$$ on a code-signing certificate more than I trust a developer who doesn't. Even if it's just $20. Why? If I expect to make four figures on spreading malware/adware, and I can assuage the nerves of people like you by spending two or three figures on a certificate, I'm going to buy the certificate and make it look all nice and pretty and take your money. >…

They didn't say they trust the developer who spends the money absolutely , they said they trust the developer who spends the money more than they trust one who doesn't. Which is fair -- as you note, not every scammer will be scared off by the need to spend some money to pull the scam off; but some will, so the ratio of legitimate developers to illegitimate ones will be higher in markets where there's some cost to ent…

The good scammers absolutely will not be scared off by the need to pay a penny to steal a dollar. You have to buy a cheap watch/violin/purse if you want to pass it off as an expensive one. You have to pay off in the back of the operation if you want to keep cash coming in through the front. Indeed, one of the easy ways to short-circuit human trust defenses is to make a show of trust first, such as by placing personal assets at risk. "Here, I'll trust you to hold my wallet full of $500 cash, while I drive your expensive late-model car--that's worth even more when shipped to mainland China--to go get help. You know I'm coming back, because $500 is a lot of money."

The scheme shifts the need to trust from Random Q. Hacker to the certificate-issuing authority, and that only helps if the authority is more trustworthy than the individual. If they don't put forth an effort to really dig in to those applying for certificates, they're just selling costumes for the security theater.

I trust Microsoft more than someone I have never heard of, but I don't inherently trust them more than the informal assembly of Notepad++ contributors and lead FOSS developer Don Ho. If Microsoft's code-signing certificate validation process is not capable of recognizing organizations that are not formally incorporated, and allowing them to use the name of their brand, rather than the names of their lead developers or maintainers, they are leaving a huge fraction of my installs hanging in the wind.

Re: Notepad++ drops code signing for its releases

#195
post #86
post #70

Windows signing is a ripoff, $500/year you're getting nothing. Your certificate is not trusted. You have to "get reputation for it" before Windows Defender would stop giving users warnings. Also, renewing certificate is not a thing. Every time you have to get a new one, with same story of "reputation" again. [1] https://www.digicert.com/order/order-1.php

You can get a certificate far cheaper than that - K-Software offer them for $85/year. I've used them for years and can recommend them.

I recently got an $85 certificate from k-software which is actually Comodo now Sectigo. It was a nightmare. Took two months and fifty emails.

Re: Notepad++ drops code signing for its releases

#196

I created a huge rant on code signing certificates here: https://www.youtube.com/watch?v=mwuk0E-tfeg It's a nightmare. Complete scam. I needed this for Polar: https://getpolarized.io/ Mind you... it's Open Source but I still want my users to be able to download it without warnings. No joke - it took me 2 weeks to get the CSC with about 4 hours per day working on just this CSC issue. It's just a labyrinth of insanity…

For those that don't know, D&B stands for Dun & Bradstreet ( https://www.dnb.com/ ). They have this concept of a D-U-N-S Number which basically means information about your business is in their database. Last I checked expedited D&B was around $40 USD (10 business days) and same-day D&B around $500 USD. Free D&B said it would take 30 business days, but it actually only took them 5 business days when I applied for it.

If you sell software to the government, having a DUNS number is actually a requirement, too. At least to get listed on SAM.gov. You also need a CAGE number. I don't remember it taking me too long to get a DUNS number - and you can definitely avoid paying them any money.

Re: Notepad++ drops code signing for its releases

#197

I'm going through a "renewal" right now... The archaic maze of validation is also getting on my nerves. It's been three weeks now that I'm waiting for a phone call to validate my phone number. This article is making it so tempting to cancel my order. The plethora of support emails is what motivated me to get one in the first place. I used to get accused of giving users a "virus" and getting into infinite loops on why…

Is it k-software/Comodo/Sectigo by any chance?

Re: Notepad++ drops code signing for its releases

#198

Earlier quoted context omitted.

Not sure how it managed to take you so long, but I do agree it's a PITA, and pure theatre. I did need to get into D&B, and it was a bit of a faff - their website is a maze, and it took around a week after filling the form to get listed. Didn't need much time on it though. One of the other requirements I had to fulfil was having a telephone number published in a sanctioned list of websites for a callback - so I regist…

There might be some risk to your business if a malicious person can get that number assigned to their phone since you're no longer using it.

Not sure I see how, but it was only listed for 24 hours in any case.

Re: Notepad++ drops code signing for its releases

#199
post #70

Windows signing is a ripoff, $500/year you're getting nothing. Your certificate is not trusted. You have to "get reputation for it" before Windows Defender would stop giving users warnings. Also, renewing certificate is not a thing. Every time you have to get a new one, with same story of "reputation" again. [1] https://www.digicert.com/order/order-1.php

> Also, renewing certificate is not a thing.

Oh, no. We just kept renewing our EV certs with them for past several years... if only we'd known that we can't. Damn. Such an amateur shop this Digicert. Unacceptable.

Re: Notepad++ drops code signing for its releases

#200
post #169

Earlier quoted context omitted.

Your trust is misplaced; a developer who drops $$$ on a certificate could be a dyed-in-the-wool criminal. Just because code is signed and certified doesn't mean it doesn't do anything bad. Signing and certificates revolve around trust/mistrust in the delivery channel not in the purveyor. That problem can be solved with other tools, like PGP. You don't have to be blackmailed by a platform's certificate racket.

> That problem can be solved with other tools, like PGP. You don't have to be blackmailed by a platform's certificate racket. It kind of works that way in Linux world where artifacts are PGP signed and to get your key into distro store one has to have "reputation". With the caveat that different distros have different schemes. X.509 used by Windows has two nice properties that PGP doesn't - certificate attestation (M…

> It kind of works that way in Linux world where artifacts are PGP signed and to get your key into distro store one has to have "reputation". With the caveat that different distros have different schemes.

... none of them financial.

I'm not saying that financial incentives are bad, necessarily, but I am saying that being able/forced to buy your way in privileges the most organized scammers, the ones who have a cogent business plan to make money from their chicanery and some seed capital, over programmers who don't have money, have no expectation of making money, and are only motivated by getting their code out there and used.

Debian has a Social Contract. Microsoft has a pricetag. I know which of them Adobe is more comfortable with.

Post reply on HN