4 ms·
Where do I sign for a petition to have a free CA like LetsEncrypt for Code Signing?
by tabulatouch 8y ago
Where do I sign for a petition to have a free CA like LetsEncrypt for Code Signing?
- drexlspivey 8y agoYou don't get to sign a petition for someone else to work for free
- mises 8y agoMaybe OP is willing to help. And in any case, it's still useful. What if he's trying to run a FOSS project and doesn't have $500 for a cert? I would say that's different than someone walking around saying "I want".
- zamadatix 8y agoWho said anything about people working for free? That's not how the example (Let's Encrypt) works so why are you bringing it up now?
- gambler 8y agoLetsEncrypt is a hack to get HTTP encryption working without shelling out money for meaningless identity "verification". Code signing has nothing to do with encryption, so having analogous CA for code would be entirely meaningless. What does code signing in Windows actually verify? That executable's author at some point paid money to some company that Microsoft deemed an "authority"? It's a rotten system. The whole CA pyramid is bullshit. What we really need is a way to know that executable notepad++2.0 is signed by the same person who signed notepad++1.0 already installed on your computer, and that it's the same person who controls notepad-plus-plus.org, and that this identity has existed for well over 10 years. This is legitimately useful info that would allow people to make more informed decisions about what to install. BTW, the part about historic record seems like one of the few good uses for blockchain technology.
- smarx007 8y agoNo, it verifies that the certificate was issued to someone whose ID was checked. Money is paid for the covering the bureaucratic costs and keeping the records etc.
- gambler 8y agoProblem is, this assumes that all CAs and their resellers do that verification properly. https://security.googleblog.com/2015/03/maintaining-digital-certificate-security.html https://security.googleblog.com/2015/03/maintaining-digital-... https://arstechnica.com/information-technology/2017/11/evasive-code-signed-malware-flourished-before-stuxnet-and-still-does/ https://arstechnica.com/information-technology/2017/11/evasi... "The third key weakness in the code-signing ecosystem was the failure of certificate authorities to verify the identities of people applying for code-signing certificates. Twenty-seven certificates in the group of 111 misappropriated certificates that the researchers identified fell into this class. Twenty-two of the certificates were improperly issued as a result of identity theft of a legitimate company. In some cases, malicious actors impersonated legitimate companies, in some cases ones that had no involvement at all in publishing software. In the remaining five cases, the certificates were issued to fraudulent shell companies. "
- theandrewbailey 8y ago> LetsEncrypt is a hack to get HTTP encryption working without shelling out money for meaningless identity "verification". Have you used Let's Encrypt? It verifies that you own the domain in question. HTTPS requires that the server you're connecting to has been identified.
- mises 8y agoAbsolutely agree, though the "reputation" racket remains. The problem with EV (and the reason why Let's Encrypt doesn't provide them for SSL) is that such certificates must be tied to a legal entity.
- GordonS 8y agoI asked about this before, a while back. I seem to recall they said they won't do it, because the verification required is completely different - they'd need to verify your organisation, rather than a domain.
- Someone1234 8y agoCode Signing is more akin to EV than domain verified. They're checking organisational or individual identity, which is a work intensive process (e.g. "email me your driver's license, business license, and tax return so I can manually review them.") It might be possible for a charity to run a FOSS code signing CA, but it is unclear who's paying for that since it needs actual staff.