4 ms·
>(minus the windows UAC thing) As Windows only project, UAC is the only thing that matters in this equation.
by mariusmg 8y ago
>(minus the windows UAC thing)
As Windows only project, UAC is the only thing that matters in this equation.
- kpcyrd 8y agoI've just edited my comment to make this clearer. Doing code signing with signify or pgp gives you a way the verify the binary you downloaded is actually the file the developer built on their laptop, even if the webserver is compromised. Linux ISOs are very commonly distributed that way. I agree that it's extremely uncommon for windows users to verify this though.
- prepend 8y agoWindows does not care about non-windows recognized signatures. So this works fine for users who care about gpg verification, but fails the “Windows doesn’t prompt me about insecure stuff” test.
- someguydave 8y agopresumably the user who understands how GPG signing works also doesn't care what windows thinks