3 ms·
Microsoft can give out free code-signing certificates like LetsEncrypt, but bind publisher reputation to the domain name, rather than to a particular public key
by mkup 6y ago
Microsoft can give out free code-signing certificates like LetsEncrypt, but bind publisher reputation to the domain name, rather than to a particular public key or certificate. In such way, malware makers won't be able to build up enough reputation, because they will have to switch domain names often (and legit software publishers won't be subjects to extortion by Code Signing CAs). Regarding domain expiry problem, this is solved by short-lived certificates (same as for LetsEncrypt) and timestamping server.
- captn3m0 6y agoThis enforces a "developers-must-own-and-continue-to-own-a-domain". Not saying that's bad, but it needs to be considered. for eg A lot of software these days is built and served entirely from GitHub. You could even end up re-using domain-name-signals from existing spam datasets (whois, hosting provider, age etc).
- Wowfunhappy 6y ago> This enforces a "developers-must-own-and-continue-to-own-a-domain". Not saying that's bad I'll come out and say it's bad... but also much better than the current situation. So as a compromise I'm all for it!
- mopsi 6y ago> A lot of software these days is built and served entirely from GitHub. The identity could also be tied to Github accounts, among other options.
- donmcronald 6y agoA domain is $10-$20 / year. I’ll take that over $500 / year EV code signing certificates.
- donmcronald 6y agoYes. Domains, long lived private keys, developer accounts, etc. are all better than the current system. If timestamp countersigning were replaced with some kind of domain based validation we could have short lived keys and the whole thing could be tied back to a digital identity that’s more trustworthy than Malware Inc.’s EV code signing certificate.