6 ms·
Why are the macOS and Windows versions are unsigned?
by danieldk 7y ago
Why are the macOS and Windows versions are unsigned?
- tiborsaas 7y agoIt costs money
- danieldk 7y agoIsn't Jitsi co-developed/sponsored by 8x8? An Apple developer account costs 99 per year. If the money is a problem, a lot of people would probably donate some amount if that helps getting signed releases. At any rate, I think having unsigned binaries that are not notarized introduces additional hoops for non-expert users, since macOS requires signed bundles by default (which is a good thing!).
- ckcheng 7y agoIsn't the hoop just right-click and choose open? Or is there something more nowadays?
- httpsterio 7y agoin some cases, it can't be installed at all depending on the privileges.
- Cyberdog 7y agoIf by "hoop" you mean "workaround," yes. But normies are used to starting applications by double-left-clicking them, and there's nothing in the error message that appears after that indicating it can be worked around. Unless the normie thinks to ask a friend or the internet how they can go ahead and open the app anyway, they'll never find out about it. To come at it from another direction, why is it your users' responsibility to work around your own cheapness/laziness? Just front the $100 and sign your damn app, especially if you're making money with it.
- danieldk 7y agoAs Cyberdog says, the hoop is that a lot of regular users do not know about. Moreover, signatures and notarization are there for a reason. Code signing makes it more likely that the bundle was not tampered with. Apple can revoke the certificate if the developer key leaked. Notarization will catch at least some forms of malware. I refuse to run unsigned code (with one exception), because it decreases security significantly. There have also been severe incidents in the past with unsigned code, e.g.: https://blog.malwarebytes.com/threat-analysis/mac-threat-analysis/2017/05/handbrake-hacked-to-drop-new-variant-of-proton-malware/ https://blog.malwarebytes.com/threat-analysis/mac-threat-ana...
- vpl 7y agoJitsi Meet is already on the iOS App Store. That would mean they already have an Apple developer account with which they could sign the Electron app.
- Cyberdog 7y agoIt costs $100 a year to sign Apple programs (last time I was doing it). Jitsi has a corporate sponsor. Nobody involved with Jitsi could swing it? Really?
- davej 7y agoWe can help here. We'll do it free. Jitsi guys: Email me dave[at]todesktop.com.
- oefrha 7y agoNot sure I understand your offerings. You seem to suggest that you offer code signing without an Apple Developer subscription? So are you using your own certificates to sign your clients’ code? If that’s the case it sounds like you’re probably breaking TOS and opening up your clients to immense risk: one client’s abuse results in all clients’ apps revoked.
- codegladiator 7y agoedit: nvm
- oefrha 7y agoUnless free actually means a cash allowance (which would be very generous), I don’t see how this would work. I’m certainly not gonna let someone else register and pay for an Apple Developer account on my behalf.
- davej 7y agoOur customers provide the certs. We can sort something out for Jitsi though. They are on the app store so they most likely already have a cert.
- oefrha 7y agoOkay, that’s more reasonable.
- tiborsaas 7y agoThis is just one of my guess here. If you look at the commit history the project doesn't look like being the main focus. Code signing is not as streamlined as Let's encrypt, the money part makes it bumpy, so I'm not surprised.
- pornel 7y agoI understand not signing on Windows — it's a nightmare of incompetent, but expensive CAs, and unusable poorly documented mostly-broken tooling from the '90s. And in the end it hardly does anything, as you still get the executable blocked for a month. But for macOS it's way easier, and more needed. It actually silences the scary warnings. It's even a real security improvement, as you get your app's keychain protected.
- anaisbetts 7y ago> And in the end it hardly does anything, as you still get the executable blocked for a month. This is very much not true - if you have unsigned executables for an app of any scale, 3rd party AV will be extremely Unkind to your app, especially if you try to do updates. Also, how long your app gets blocked depends on how many downloads you get, if your app is popular it can be unblocked in a matter of hours, and once a download URL is deemed trusted, this is largely a non-problem. Also, while I'll 100% agree that CAs on Windows are a nightmare, the tooling is extremely straightforward, signtool.exe takes your cert file, a password, and an executable, then signs it.
- pornel 7y agoExcept when the signtool.exe defaults to SHA-1, generating a signature that Windows won't accept. And then you need to add an arg for a timeserver. And args in a wrong order just silently generate a useless signature. And documentation for all of it is mostly from IE5.5 era, fragmented over several unfinished reorganizations of MSDN. And tooling for managing the certs is another pain. Mine required entering a PIN from a GUI every time certs were touched, so I couldn't automate the builds.
- ComputerGuru 7y agoIt’s absolutely none of those things. $300 for five years and a single executable to do the signing with.
- DerWOK 7y agoAuthors explain why code signing (currently) was skipped here: https://github.com/jitsi/jitsi-meet-electron/issues/234#issuecomment-610793581 https://github.com/jitsi/jitsi-meet-electron/issues/234#issu...