Earlier quoted context omitted.
> With that kind of money they can pretty much bypass any measure an OS manufacturer could reasonably put in place Exactly. That's why this should just stop. Because it hurts without helping.
> That's why this should just stop So they should stop (discontinue) every measure that can be bypassed by an outfit with this kind of money? That doesn't leave many measures, if any. And it lowers the bar for a successful attack to someone with a couple of hours to spare. SmartScreen prompts are just like any HTTP error in a browser. The cert certifies an identity, that's it. It doesn't magically clean any malware i…
Nobody needs to charge money for me to be able to sign my executables with something like PGP.
> The cert certifies an identity, that's it. It doesn't magically clean any malware inside, that you know the identity, or that you have to trust it.
And yet the message is very clearly "THIS IS UNSAFE" because "WE don't know the guy". It isn't "Don't run"/"Run anyway thanks." It's "DON'T RUN" in BOLD in an eye-catching bright box in a prominent location where buttons go and "(more info)" in body text somewhere else.