Live data from Hacker News

The Windows installer of ImageMagick will no longer be signed

github.com

171–180 of 364 posts

Re: The Windows installer of ImageMagick will no longer be signed

#171
I really wish they would lower the cost of signing certificates generally. $10 tops. I can’t justify the cost for my very specialized software very few people use.

My only explanation for why it needs to be so expensive is that it needs to be a large enough charge that the rightful owner of a stolen credit card might notice it? Because it’s in and of itself an author verification? If that’s the case though, they could refund some or all of it after say 3 months?

Even then, just as a verification, there seems like very little need to charge for that verification annually. It really just seems like rent seeking.

Re: The Windows installer of ImageMagick will no longer be signed

#172

It’s astonishing that a project as critical and widely used as ImageMagick can’t even scrape together $629 for something as essential as a software signature. It’s a glaring example of how the tech industry fails to financially support the very open-source projects that it relies so heavily upon. Despite offering incredible value, these projects often can’t capture enough of it to sustain themselves. It’s a sobering…

Free Software is about freedom. Not paying rent to Microsoft or their partners.

Re: The Windows installer of ImageMagick will no longer be signed

#173

Earlier quoted context omitted.

The problem is that sandboxing is an afterthought on these platforms.

That is obvious. Like saying the "sun is yellow because it is about 4.5 billion years old." Even if sandboxing was thought about back when Linus was porting Unix, it would have been extremely slow as processors and ram was very limited back then. If we could go back in time and give them ridiculously fast processors and effectively unlimited ram like we have today, I'm sure Linux and Windows (er, DOS) would look quit…

Every time a user space program makes an syscall the OS already has to go through layers of indirection. The OS can provide a program with a virtual or restricted view of the filesystem instead of the real thing just as easily. The OS already prevents processes from accessing each other's memory. There are some difficulties with sandboxing peripherals and GPU access, but for the most part sandboxing has absolutely no performance impact. Sandboxing doesn't mean the OS has to spin up a virtual machine every time you want to run a program.

Re: The Windows installer of ImageMagick will no longer be signed

#174

Earlier quoted context omitted.

Still, high profile projects should be able to raise this type of money with ease. If they would say “Would match our ‘donation’ and donate $10 each year that we put in $1k in labor to this project?” that sounds like some commercial users would accept. But the first problem with medium scale OSS like this is that it’s no one’s hobby to manage projects or beg for money. It’s also a problem that OSS contribution/sponso…

But why should they raise this money? The unspoken assumption here is that code signing is a good thing . I question this assumption, particularly with how this works today. Microsoft, the cert issuers, and other companies involved in this are trying to create a reality in which software must always be attached to a specific legal entity, and then that entity must be vetted through the "corporate web of trust". That…

As the comments on the issue suggests, $629 is not the minimum price tag. It can be much cheaper without being more complicated.

But I agree Microsoft could probably make it easier and cheaper but I can’t see why they would want that given they want to drive apps to stores and not self publishing. They want the bad method of publishing to have bad ergonomics.

A letsencrypt style signing process would be possible and would let people base the trust on the ownership of company.com instead of a regular cert. And for most use cases this seems good enough.

Re: The Windows installer of ImageMagick will no longer be signed

#176
post #72
post #65

Earlier quoted context omitted.

you see it as a failure of the tech industry to finance open source. I see it as a failure to provide security systems like this without the need for financial gatekeeping. $629.00 isn't a trivial amount of money.

Considering the scale of ImageMagick- $629 is a very, very small amount of money considering the value that IM has generated.

629 centss, Or 6 cents, is too much. It’s not the cost, it’s the walled garden. Same with iPhone development - at least when I looked at it - you couldn’t it’s download a Free sdk and get hacking, you had to apply and agree to all sorts of onerous legal restrictions.

Compare that to the days of dos, where you could type “qbasic” and away you went

Re: The Windows installer of ImageMagick will no longer be signed

#177
post #90

Earlier quoted context omitted.

This way of working should have been left behind in the previous century. Sandboxing should be default. Associating file endings should be a suggestion to the OS, accepted by the user, not something only configurable by delegating full super admin to third party app. Slow loading context menus where every app tries to claim its presence. Thank you for reminding me why I don’t use Windows since years ago. A image edit…

Windows has already made that journey years ago. The MSIX system works the way you suggest: • Admin privs aren't needed • Packages declare what integration points they need in an XML file It's similar to the way macOS, iOS and Android work. You can also (starting soon in Win11) declare that the app will be sandboxed. However, developers have to actually use this system and most don't know it exists or how to use it.…

> The ImageMagick developers can fix their problem by purchasing a cheap OV code signing certificate and then using Conveyor

By "cheap" you mean $500/year[0]? Then for anyone who isn't open source it's another $45/month on top for Conveyor. That's hardly "accessible".

That said, Conveyor looks awesome. We (thankfully) distribute our application via Steam/EGS/etc but when we were looking at bundling installers before that it was a nightmare and we probably would have just paid for Conveyor.

[0] https://order.digicert.com/step1/code_signing

Re: The Windows installer of ImageMagick will no longer be signed

#178
post #69

Earlier quoted context omitted.

> I would love to see a LetsEncrypt style service for OSS but I assume it's against the core interests of Microsoft / Apple to allow something like this as it would start to drive people away from the walled gardens of the app stores. People have been asking Let's Encrypt itself for this on the Let's Encrypt forum since the project was founded. The usual answer is that code signing certificates are (supposedly) tryin…

I think it would be fine to have code signing certificate ensures that signer controls a certain DNS name. I'm fine with "installer have been signed with somebody who owns imagemagick.org"

Will you notice if the software will be signed by certificate for "imagemaqick.com" or "imagemagik.com" or "imagemagick-developers.com"?

Re: The Windows installer of ImageMagick will no longer be signed

#179

It’s astonishing that a project as critical and widely used as ImageMagick can’t even scrape together $629 for something as essential as a software signature. It’s a glaring example of how the tech industry fails to financially support the very open-source projects that it relies so heavily upon. Despite offering incredible value, these projects often can’t capture enough of it to sustain themselves. It’s a sobering…

> can’t even scrape together $629 for something as essential as a software signature I don't think the $629 itself is the problem, but rather that they're being forced to spend it on something that many people don't agree is "essential" in any way. Is it about security, or is it about crying "security" to push through a pay-to-play market?

> but rather that they're being forced to spend it on something that many people don't agree is "essential" in any way.

Putting the price aside just for a second, are there really people out there who think that code signing isn't worthwhile? Remember paint.net/filezilla having ad links to "Download Now" that would download... not paint.net or filezilla?

Re: The Windows installer of ImageMagick will no longer be signed

#180
So much for 'Developers, developers, developers!'.

If there is one thing that seems to be common amongst large tech companies it is that it all starts out looking great, then after a few years the rot sets in and if they manage to hang on long enough eventually they turn into parasitic entities. There is no way that a company the size of Microsoft could not come up with a way of working that would enable the FOSS world that they claim to be such huge supporters of to deploy on their platform without hassle or cost. All of this friction in the name of security always accidentally helps the bottom line.

Post reply on HN