2 ms·
> And that is to say nothing of the risks you take these days online by publishing your legal name. I understand that you're in a risky line of “business” with
by beefhash 7y ago
> And that is to say nothing of the risks you take these days online by publishing your legal name.
I understand that you're in a risky line of “business” with emulation, where one wrong step can get you some lovely letters from lawyers. However, for the sake of argument: Is there any reason you couldn't get someone else to lend you their name so that they act under their real name for you? Surely that'd be an option for risk-averse people.
> In my own case, this has effectively prevented me from releasing compiled binaries of my own software going forward. If code signing is a requirement to distribute free software, then we need a Let’s Encrypt-style alternative for code signing—yesterday.
The whole point of a code signing requirement is to add a paywall so that only two kinds of people will have access to it: Bad actors sophisticated enough to steal a code signing certificate from someone who has purchased them.
It's a net gain for security. Software freedom, considering increasingly prevalent SaaS and closed-source apps on mobile devices, is already lost. So if we've already lost software freedom—as far as I can tell, more or less irrevocably—then we might as well at least reap the security benefit for the common person while we're there.
- gerikson 7y ago> Is there any reason you couldn't get someone else to lend you their name so that they act under their real name for you? Surely that'd be an option for risk-averse people. This just pushes the problem up a level. The front-person would assume the legal risk, and if they're trying to avoid it they will let the legal system know the "real" person. IRL there are "goalies"[1] - indigent individuals who for a low price will assume the legal risk of, for example, registering ownership of a car. This is a grey area indeed. [1] translation of the Swedish term "målvakt", from where I know of this phenomenon.
- near 7y ago> However, for the sake of argument: Is there any reason you couldn't get someone else to lend you their name so that they act under their real name for you? It's possible, but I would find it to be rather unethical. I am much more willing to allow an EV certificate to sign my software, or if I could get the BBB to respond to my requests to register with them, I could even consider purchasing my own EV certificate for my LLC. (my understanding is that the EV validation process confirms your business' validity through its BBB listing, and an article of incorporation is not enough.) > The whole point of a code signing requirement is to add a paywall so that only two kinds of people will have access to it Why is the web and Let's Encrypt any different? Websites execute code that can potentially harm your computer (via zero-days.) A paywall harms free software developers who can't afford hundreds of dollars a year for certificates, which is not a problem for me, but would be for many folks.
- lupire 7y agoLocks and keys harm poor people who can't afford them. Filtering water harms poor people who can't afford to remove pollution. Blame the criminals, not the security providers and consumers.
- beefhash 7y ago> Why is the web and Let's Encrypt any different? Websites execute code that can potentially harm your computer (via zero-days.) The web is as much of a remote code execution vehicle as it is an application platform that could theoretically do a lot of things without the remote code execution in the form of wasm/JavaScript. TLS solves the issue of people eavesdropping passively and MITM actively to do real-world harm by stealing credentials or injecting malware: It was a solution to an actual problem. Don't get me wrong, I am very much advocating for requiring TLS EV certificates if you serve JavaScript or WebAssembly once we've finished purging the plaintext web. It's a necessary evil to get more accountability for code and subsequently ease prosecution for hosting and distributing malware. People downloading and executing other people's code is also a problem in need of a solution because of the very much non-trivial risk of malware these days. App stores have worked on mobile (at least it's improved the mobile threat landscape compared to traditional desktop computing). The idea of an app store can be made to work for desktop computers as well to reap the same security benefits of having a central, reviewing gatekeeper that is subsidized by everyone publishing there to pay a cost. The proper solution would be to have mobile-like sandboxing capabilities on Windows, macOS and Linux, but that's still far. Mandatory code signing with personal identification is just a stopgap measure. > A paywall harms free software developers who can't afford hundreds of dollars a year for certificates, which is not a problem for me, but would be for many folks. I don't deny that this is a problem for many folks. But this assumes (executable) free software is desirable. It isn't. End-user software should be must be made at a loss (time) or for profit. This just makes the loss much more economically explicit. In the long run, this could give back value to software in the perception of users, which I consider to be a good thing.