Your idealism and enthusiasm for this is charming!
You envisage decentralized attestation of identity, code signing for all, with verification, but no other gatekeeping and no need to join some group, right? Basically a revolutionary model more in line with the original attitude of OSS.
It's a cool idea, I hope you pursue it!
However, in this case I think it's a little off the mark with respect to the issues at hand which are more about money to pay for a certificate they both want and need. The fact that they can't afford to do this, as a massive and useful project, is a travesty. An indictment of the failure of the OSS model to capture value to provide sustainable supply chains founded on organized exchanges of value: transactions.
I get the anti-corporate idealism in your post, and it makes sense! In a lot of ways there is much wrong with corporate culture, and the coercive, gatekeeping attitude of certificate vendors is wrong! Like a cartel, as I said.
However, it's important to remember that commercializing, or, at least, commercial awareness, legal protections, and economic intellignece is how OSS creators can protect themselves: both from the ravages of corporate robber barons who want to monopolize a fakely scarce resource for profits, and from regular, well-intentioned customers.
Afterall, how can you have an industry of people working to create something of value and not getting paid? It doesn't work.
I think you miss the big picture here, not me. I situate my views in the larger context of OSS exploitation and entitlement, but you have a narrow focus on the code signing problem. Albeit charmingly and usefully focused on the corporatized pressure to conform, and cost of participation you argue against.
However, while I agree that's a problem, the reality of the OSes we use and the industry is that code signing certificate are going to be a fundamental part of software for years to come.
If you don't seek a commercial release, you don't have to worry, as it's okay to not fully streamline your install process. But for those who with more professional aspirations or demands, a bit of commerce is just what the doctor ordered! :)
And the issue of exploitation of OSS extends far beyond code signing. So you may as well figure out how to commercialize, is what I'm saying. Because commercial awareness is how you can protect yourself.
It may not seem important, and indeed it isn't if you don't have a market. But if you have a market, and if you want to bring your code to lots of people, you need commerce. Otherwise it's just exploitation and entitlement. Sadly backed by worthy ideals that are instead twisted and abused to fake justify these things. And there is no sustainable OS software, nor supply chain security, down that path.
While the shadow of capitalism indeed has a long dark tail, and your skepticism of commercialization is understandable, it doesn't have to be all doom and gloom. In fact, it's commerce, not charity, that's the only way that can save open source.
Thank you for your comment! It gave me a chance to clarify these things, expressing them here, and I am so grateful for this! :)
PLease work on your decentralized code signing, it sounds really cool!