Live data from Hacker News

Notepad++ drops code signing for its releases

notepad-plus-plus.org

221–230 of 335 posts

Re: Notepad++ drops code signing for its releases

#221
post #63

Earlier quoted context omitted.

"the good old days", as in, "the days when the average person had no freaking clue if something was safe, but installed it anyway because it's completely unreasonable to expect them to do otherwise"? If your security model is "do your research" then you're going to fail.

Just because someone certifies that it wasn't tampered with and comes from who it says it does doesn't mean it is safe.

A novel idea. Apple and googles own apps have been tampered with. Indeed there are compromised apps available for download now on both stores.

Perhaps it's 'safer' but now we all ask permission and pay a huge tax to release software.

Is this a better system?

The web is alive but under attack. What freedoms will devs have left?

We will either pay comcast or we will pay google and apple. Either way the entrance fee for development just became a lot higher.

Re: Notepad++ drops code signing for its releases

#222

Earlier quoted context omitted.

They didn't say they trust the developer who spends the money absolutely , they said they trust the developer who spends the money more than they trust one who doesn't. Which is fair -- as you note, not every scammer will be scared off by the need to spend some money to pull the scam off; but some will, so the ratio of legitimate developers to illegitimate ones will be higher in markets where there's some cost to ent…

It is not fair. The same cost in money does not translate to the same cost in efforts to earn trust. This is structural discrimination.

You are not necessarily in disagreement with the poster you responded to. They meant it was fair in the sense that the user is using a fair heuristic to determine how likely they are to be scammed. You're saying it's unfair to the person who made the software, as they are experiencing structural discrimination. Those two points are not mutually exclusive.

Re: Notepad++ drops code signing for its releases

#223

Earlier quoted context omitted.

They didn't say they trust the developer who spends the money absolutely , they said they trust the developer who spends the money more than they trust one who doesn't. Which is fair -- as you note, not every scammer will be scared off by the need to spend some money to pull the scam off; but some will, so the ratio of legitimate developers to illegitimate ones will be higher in markets where there's some cost to ent…

The good scammers absolutely will not be scared off by the need to pay a penny to steal a dollar. You have to buy a cheap watch/violin/purse if you want to pass it off as an expensive one. You have to pay off in the back of the operation if you want to keep cash coming in through the front. Indeed, one of the easy ways to short-circuit human trust defenses is to make a show of trust first, such as by placing personal…

I don't disagree with your reasoning. But: I posit there are fewer "good scammers" than "scammers." Added friction probably reduces the total number of active scammers.

Re: Notepad++ drops code signing for its releases

#224

Reading these comments makes me so happy to be a Linux/BSD user. The hoops you guys have to jump through in proprietary land. Wow, pay $$$ to be treated like shit. It's kinda like those guys that hire a dominatrix to belittle them and make them lick her heel, yet they get off on it.

Could you please stop posting unsubstantive comments and/or flamebait to HN? We're trying for something higher-quality than that on this site.

https://news.ycombinator.com/newsguidelines.html

https://news.ycombinator.com/newswelcome.html

Re: Notepad++ drops code signing for its releases

#225
post #207
post #200

Earlier quoted context omitted.

> It kind of works that way in Linux world where artifacts are PGP signed and to get your key into distro store one has to have "reputation". With the caveat that different distros have different schemes. ... none of them financial. I'm not saying that financial incentives are bad, necessarily, but I am saying that being able/forced to buy your way in privileges the most organized scammers, the ones who have a cogent…

> I am saying that being able/forced to buy your way in privileges the most organized scammers This works both ways because legitimate software developers also don't have easy ways of pushing their signed software to end users. Usually step 1 in installing software from external developer is "get my PGP key imported" [0]. [0]: https://www.sublimemerge.com/docs/linux_repositories I don't mean Linux distro's model is w…

> Usually step 1 in installing software from external developer is "get my PGP key imported" [0].

Even #%@! Oracle does it:

https://www.virtualbox.org/wiki/Linux_Downloads

I wonder what’s the point of the PGP key then.

Re: Notepad++ drops code signing for its releases

#226
post #224

Reading these comments makes me so happy to be a Linux/BSD user. The hoops you guys have to jump through in proprietary land. Wow, pay $$$ to be treated like shit. It's kinda like those guys that hire a dominatrix to belittle them and make them lick her heel, yet they get off on it.

Could you please stop posting unsubstantive comments and/or flamebait to HN? We're trying for something higher-quality than that on this site. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newswelcome.html

As you wish, I'll keep my opinion to myself.

Re: Notepad++ drops code signing for its releases

#227
post #46
post #29

Earlier quoted context omitted.

I've just edited my comment to make this clearer. Doing code signing with signify or pgp gives you a way the verify the binary you downloaded is actually the file the developer built on their laptop, even if the webserver is compromised. Linux ISOs are very commonly distributed that way. I agree that it's extremely uncommon for windows users to verify this though.

Windows does not care about non-windows recognized signatures. So this works fine for users who care about gpg verification, but fails the “Windows doesn’t prompt me about insecure stuff” test.

presumably the user who understands how GPG signing works also doesn't care what windows thinks

Re: Notepad++ drops code signing for its releases

#228
post #53
post #25

Earlier quoted context omitted.

>I remember the good old days when people were actually trusted to do their own research before downloading a potentially dangerous exe. Is there any evidence that was ever really a thing / effective? How could you possibly know? There are plenty of examples of previously trustworthy software becoming untrustworthy, same with sites you download the code from. That line reads like the absurd advice that security exper…

The existence of whole industrial and home computer industry kinda proves that the models were effective and worked. Yes, there were vulnerabilities and viruses but that did not stop the computer industry from growing and proving its worth.

This is true, but "worked" does mean it was secure by whatever we standard we consider good today.

That might be because we (at least on sites like this) are being overzealous about security. Or it might mean that in the modern environment, security is more of the concerns than in the halcyon days of MS-DOS.

Re: Notepad++ drops code signing for its releases

#229
post #70

Windows signing is a ripoff, $500/year you're getting nothing. Your certificate is not trusted. You have to "get reputation for it" before Windows Defender would stop giving users warnings. Also, renewing certificate is not a thing. Every time you have to get a new one, with same story of "reputation" again. [1] https://www.digicert.com/order/order-1.php

Funny thing about trust: I trust a developer who drops some $$$ on a code-signing certificate more than I trust a developer who doesn't. Even if it's just $20. Also, the validation requirements to obtain a code-signing certificate, while certainly not bulletproof, are not nothing: you need to send in articles of incorporation and your business needs a listing with a physical address and phone number in a public direc…

Well I don't care if the developer payed the certificate, and I don't see why someone that develops FOSS should pay money for something that doesn't bring to him any of that money back. At least for open source software certificates should be offered for free, in my opinion.

Also the fact that you are required to have a corporation, why? If I develop again an open source software I need to register a corporation just to deploy that software on Windows the correct way? That is total bullshit for me, just let me sign my software like is done on other platforms for nothing or a very small fee and done.

Re: Notepad++ drops code signing for its releases

#230
post #114

Earlier quoted context omitted.

Funny thing about trust: I trust a developer who drops some $$$ on a code-signing certificate more than I trust a developer who doesn't. Even if it's just $20. Also, the validation requirements to obtain a code-signing certificate, while certainly not bulletproof, are not nothing: you need to send in articles of incorporation and your business needs a listing with a physical address and phone number in a public direc…

> Funny thing about trust: I trust a developer who drops some $$$ on a code-signing certificate more than I trust a developer who doesn't. Even if it's just $20. Why? If I expect to make four figures on spreading malware/adware, and I can assuage the nerves of people like you by spending two or three figures on a certificate, I'm going to buy the certificate and make it look all nice and pretty and take your money. >…

I mean, if someone is going to commit a crime, forcing them to leave a paper trail is going to scare at least some of them off. And if I'm installing Adobe Photoshop, and the cert comes from Bob's Software Emporium, Delaware, it raises questions.
Post reply on HN