> We think that revoking certificates based on questionable data discredits the certification system.
It's hard to dispute this imo. There are many good reasons certificates should be revoked, but the reasoning should be 100% public information, for both the vendor and users who may have trusted the original certificate.
I'm building a desktop app, and the process to even get a certificate is absurd. Each CA has their own wildly different processes, and seemingly answers to nobody. I changed cert providers recently after Digicert suddenly raised their prices 400% on a whim, and it took a huge number of changing requirements, phone calls, 3rd parties, and over a month to receive the new one, despite already having an existing verified & still-valid signing certificate with all those details from an equally legitimate provider.
I'd kill to see a modern service a la Let's Encrypt but for code signing. Something transparent, reliable, fast & trusted cross-platform (I can dream). Verifying identity is a hard problem, but it's really not _that_ hard a problem - there's plenty of fintech services that can reliably do sufficient KYC for banking in 5 minutes with a few id details and video call.