Live data from Hacker News

How not using Internet Explorer put me out of touch and cost me dearly

blurity.com

11–20 of 141 posts

Re: How not using Internet Explorer put me out of touch and cost me dearly

#11

I know some people have voiced concerns about Gatekeeper in 10.8, but this seems at least as bad. Especially from a normal user's perspective.

Gatekeeper is not nearly as bad for small developers, though. Unless Microsoft has started offering, as part of a $99 MSDN subscription, the ability to generate a signed certificate that doesn't expire for five years automatically from inside Visual Studio as soon as you've signed in with your Microsoft ID.

The problem with Microsoft's strategy has always been the reliance on companies like VeriSign for whom recurring revenue from certificate renewal is a primary revenue source. And when I've had to deal with VeriSign for code-signing certificates in the past, it's easily cost more than $99 in time ("I'm sorry for the delay, but could you please fax that to us again, only this time, on official company letterhead?").

Re: How not using Internet Explorer put me out of touch and cost me dearly

#13
While that is nice to know, it still smells of Raketeering to me.

"that is some nice software you have there, would be a shame if users thought it was dangerous"

"pay a little money to one of these approved companies and that warning will go away"

If MS was serious about this only being for security they could issue the certificates for free and prove me wrong.

On the other hand, why is it that about 20% of users click past BOTH of these EXTREEMLY scary warnings? Don't they read them at all?

Re: How not using Internet Explorer put me out of touch and cost me dearly

#14
post #5
post #3

If you are creating a Windows binary and expect a user to download it, you should be signing the binary. Period. It's not just IE that considers unsigned downloads suspect, many antivirus programs do as well. If you are proud of your work, sign it.

Maybe I'm too proud of my work to give in to certificate blackmail??

That's nice, but you can't eat dignity. :P

Re: How not using Internet Explorer put me out of touch and cost me dearly

#15

I know some people have voiced concerns about Gatekeeper in 10.8, but this seems at least as bad. Especially from a normal user's perspective.

Gatekeeper is not nearly as bad for small developers, though. Unless Microsoft has started offering, as part of a $99 MSDN subscription, the ability to generate a signed certificate that doesn't expire for five years automatically from inside Visual Studio as soon as you've signed in with your Microsoft ID. The problem with Microsoft's strategy has always been the reliance on companies like VeriSign for whom recurrin…

Last I checked, you didn't even need the $99 Mac Developer program to get a signing certificate. You just needed an Apple Developer Id. The $99 program allows you to submit apps to the app store and gives you access to pre-release binaries, etc.

Re: How not using Internet Explorer put me out of touch and cost me dearly

#17
post #7
post #4

Earlier quoted context omitted.

You forgot one step: "If you are proud of your work, then buy a certificate and sign your work"

Anyone have opinions on good SSL certificate providers or do you agree with the authors recommendation of http://startssl.com ?

They do what they say they do at a decent price. However, their web interface sucks. Absolutely and completely sucks.

Re: How not using Internet Explorer put me out of touch and cost me dearly

#18
post #10

I'm no expert on these sorts of things, but it seems like the story goes something like this: 1. Dev checks out his site using IE 2. Dev realizes that IE users were getting scary warnings about his software 3. Dev has to pay up money to a third company to make the scary warnings go away. Seems like a bad state of affairs to me.

I'd love to hear how this isn't grounds for a product disparagement lawsuit. Are any attorneys familiar with SmartScreen Filter?

A couple of relevant points that may be overlooked:

1) Signing your code, even with an expensive class-3 Authenticode certificate from Verisign that allows you to sign kernel drivers, is no guarantee that IE will not accuse you of distributing potential malware.

2) Contrary to various postings by Microsoft, there appears to be no avenue for appealing IE's poor judgement calls. This happened to me a few months ago -- again, with a signed .exe -- and all of the links on microsoft.com that I followed to submit my download to a whitelist went nowhere useful.

3) Mentioned in the article but worth emphasizing: the ridiculous "This application is not commonly downloaded" criterion almost seems designed to penalize smaller vendors who release frequent updates.

This SmartScreen bullshit is one of those cases where if you're not outraged, you're either not paying attention, or you're profiting from the scam somehow.

Re: How not using Internet Explorer put me out of touch and cost me dearly

#19
post #13

While that is nice to know, it still smells of Raketeering to me. "that is some nice software you have there, would be a shame if users thought it was dangerous" "pay a little money to one of these approved companies and that warning will go away" If MS was serious about this only being for security they could issue the certificates for free and prove me wrong. On the other hand, why is it that about 20% of users cli…

>it still smells of Raketeering to me.

Congratulations - you have been enlightened to the state of PKI as it stands today. (I.e. a complete fucking scam).

Post reply on HN