Live data from Hacker News

Microsoft Defender SmartScreen is hurting independent developers

getimageview.net

171–180 of 243 posts

Re: Microsoft Defender SmartScreen is hurting independent developers

#171
post #44

I get the sentiment here, it's very annoying for developers (including me). Establishing trust is very hard problem, though. Let's move this to a productive conversation though. What can Microsoft do, as an alternative, that doesn't result in an identical or worse situation? Giving out free code-signing certificates also makes it easier for malware to get legitimate certificates. This is akin to LetsEncrypt for certs…

Absolutely. I think it's easy for the HN crowd to inadvertently forget what computers / phones / tablets / TVs look like to ordinary people. I would encourage people to come up with actual use-cases and pro-con scenarios rather than 100% "emotion mind" opinions.

So what? We are developers, we are affected, we are making ourselves heard. We aren't our users (designer's motto).

It took me about 15 minutes to get my Android Phone infected by a malware by downloading just apps from Google Play. If Google is failing in such basic task for "ordinary people", all MS accomplishes is to annoy regular developers, making their apps "suspicious" to the public.

Re: Microsoft Defender SmartScreen is hurting independent developers

#172

I call BS. This might be hurting some hobbyist projects, but anybody who earns their living publishing software, and gets even a small amount of those earnings from Windows apps, can afford $100/year for a code signing certificate. There are a lot of people trying really hard to trick users into installing software they don't want. There's big money in it. Authenticode strikes me as an entirely reasonable step to pro…

$100 USD

Re: Microsoft Defender SmartScreen is hurting independent developers

#173
post #49

Earlier quoted context omitted.

First they came for the iOS developers, and I did not speak out, because I wasn't an iOS developer. Then they came for the Windows developers, and I did not speak out, because I wasn't a Windows developer... I sure wish I could distribute the software I write without paying some rent-collector (at least) $100 for the privilege.

The problem isn't the rent. It may be an inconvenience for an indie developer, but to Microsoft, Apple, etc. the cost of a yearly developer account is peanuts. They are not doing it hoping to make excessive amounts of money. Even if Apple has a million developers paying $100, $100M is barely a blip on their radar. It is all about control. They get to decide whose software gets to run with and whose without annoyances…

> The problem isn't the rent.

Yes and no. I'm making free software for the world, not running a business, and I don't appreciate getting shaken down by a megabillion$ corporation.

Re: Microsoft Defender SmartScreen is hurting independent developers

#174

Earlier quoted context omitted.

You can recruit a clueless person to be a “virtual assistant” or similar, give them some random admin tasks (to make it feel legitimate) before sending the letter to their address and asking them to read/scan the contents for you. A similar approach is successfully used by scammers to recruit money mules.

You have to be first registered with the state and the feds (IRS) as a business which creates all kinds of legal obligations and paperwork.

You can create shell corporations anonymously where the only thing that ties you to the company is possession of the bearer bonds

Re: Microsoft Defender SmartScreen is hurting independent developers

#175
post #83

Earlier quoted context omitted.

Oh, yes, so we're supposed to believe that malware outfits bringing in millions of dollars a year in illicit profit can't afford to set up front organizations. And it doesn't even have to be fake! You could be Zoom! Or Avast! Or Trend Micro! Or Sony! Or Lenovo! The only person in this story who doesn't have a business address is me.

> malware outfits bringing in millions of dollars a year With that kind of money they can pretty much bypass any measure an OS manufacturer could reasonably put in place without completely sacrificing usability. You should see most security measures as the lock on your door. It doesn't take an expert to crack but still stops most from even attempting it. No security measure is 100% effective but it still raises the b…

> With that kind of money they can pretty much bypass any measure an OS manufacturer could reasonably put in place

Exactly. That's why this should just stop. Because it hurts without helping.

Re: Microsoft Defender SmartScreen is hurting independent developers

#176

Earlier quoted context omitted.

As someone who used to make fake IDs it would be very easy to pass EV checks. It's like putting a padlock on a gate. Anyone who wants to get past it can easily do so.

Locks only keep honest people out

They also keep people honest by diminishing the temptation

Re: Microsoft Defender SmartScreen is hurting independent developers

#177

I call BS. This might be hurting some hobbyist projects, but anybody who earns their living publishing software, and gets even a small amount of those earnings from Windows apps, can afford $100/year for a code signing certificate. There are a lot of people trying really hard to trick users into installing software they don't want. There's big money in it. Authenticode strikes me as an entirely reasonable step to pro…

$100 USD

Yes. I'll accept that thats a lot of money in some places of the world, but thats less than half a day of time for a skilled Windows developer no matter where they live.

Re: Microsoft Defender SmartScreen is hurting independent developers

#178

Apple was doing the same thing.

While there are some similarities, the key difference is that Apple doesn't impose a "reputation requirement." Signed apps and installers work the same no matter how many other users have run them.

Re: Microsoft Defender SmartScreen is hurting independent developers

#179
post #44

I get the sentiment here, it's very annoying for developers (including me). Establishing trust is very hard problem, though. Let's move this to a productive conversation though. What can Microsoft do, as an alternative, that doesn't result in an identical or worse situation? Giving out free code-signing certificates also makes it easier for malware to get legitimate certificates. This is akin to LetsEncrypt for certs…

Absolutely. I think it's easy for the HN crowd to inadvertently forget what computers / phones / tablets / TVs look like to ordinary people. I would encourage people to come up with actual use-cases and pro-con scenarios rather than 100% "emotion mind" opinions.

I don't believe any computer-illiterate people use Windows. Tablets and phones have completely replaced PCs in ordinary people's lives, with macbooks serving for the tiny percentage of tasks that need a keyboard. Anyone trying to use Windows as a "normal person" quickly runs into a bunch of random issues and edge cases, e.g. I recently realised that my microphone doesn't work right because I was plugging it into a USB3 port instead of a USB2 one. Microsoft drivers, everyone. You have nVidia drivers leaving all their previous versions installed on every update requiring use of a third party tool to clean your constantly growing C drive. You have just random driver crashes from random device manufacturers. You have at least two different control panels for every thing. And on and on. It is nearly impossible to use Windows unless you're a power user and know its workings, or have someone else administer your PC and only run MSOffice and Outlook.

That said, Smart Screen is a useful feature, I do want to know if the program I downloaded was not signed by the developer. What I would like from it however is that it should show up on every install with either "This program is signed by Malbolge Inc." or "This program does not have a signature" (in bold on bright red background with big exclamation marks border); "Do you wish to install?". Every installer gets this popup, nobody is spared. For the unsigned case, maybe require two clicks - a checkbox and a button. Because I always want to know who signed the installer, just in case I downloaded a compromised installer signed by a certificate different from what I expect. It also makes the unsigned installer popup less scary in comparison, though it must be kept visually distinct from the signed installer popup. For individual portable programs that are not installed, you will also have a "do not ask again" checkbox. Again, this will pop up for every program at least once.

Re: Microsoft Defender SmartScreen is hurting independent developers

#180
post #175

Earlier quoted context omitted.

> malware outfits bringing in millions of dollars a year With that kind of money they can pretty much bypass any measure an OS manufacturer could reasonably put in place without completely sacrificing usability. You should see most security measures as the lock on your door. It doesn't take an expert to crack but still stops most from even attempting it. No security measure is 100% effective but it still raises the b…

> With that kind of money they can pretty much bypass any measure an OS manufacturer could reasonably put in place Exactly. That's why this should just stop. Because it hurts without helping.

> That's why this should just stop

So they should stop (discontinue) every measure that can be bypassed by an outfit with this kind of money? That doesn't leave many measures, if any. And it lowers the bar for a successful attack to someone with a couple of hours to spare. SmartScreen prompts are just like any HTTP error in a browser. The cert certifies an identity, that's it. It doesn't magically clean any malware inside, that you know the identity, or that you have to trust it.

> it hurts without helping

It helps me verify that the software I use comes from the developer I expected. It may not be a catch-all but I find value in this.

Don't forget, your door lock can be opened in seconds and the person it inconveniences is mostly you, especially if you lock your keys inside. Your argument would be far more convincing if you took no precautions whatsoever because someone with millions to spend can bypass them.

Post reply on HN