5 ms·
That doesn't rate limit wealthy attackers, it just locks regular individuals out of the system. Peter Thiel could still buy 10,000 malicious certificates at $50
by gnu8 6y ago
That doesn't rate limit wealthy attackers, it just locks regular individuals out of the system. Peter Thiel could still buy 10,000 malicious certificates at $500/ea, while I wouldn't even be able to buy one for a simple project.
- a1369209993 6y agoTo be fair, the former isn't really a problem; most malware authors are profit-motivated; they're trying to scam/phish/ransomware/etc people. If you increase their operating costs sufficiently, they'll go away. The ones who can afford to eat certificate costs mostly have nation-state connections they can use to get around identity verification anyway. That said, the latter part does make this a non-starter, although the same is true of most means of identity verification, which lock out anyone with inadequate identity paperwork.
- gruez 6y ago>That said, the latter part does make this a non-starter, although the same is true of most means of identity verification, which lock out anyone with inadequate identity paperwork. I get the reasoning of "voter id laws are bad because they disproportionately disenfranchise poor people", but "code signing certificates are bad because they disproportionately disenfranchise poor programmers" doesn't really make any sense. If you know how to program, and you can pony up $300 for the code signing certificate, chances are you probably already have the requisite identity paperwork. On the off chance that you don't, it's no big deal because lots of prominent software aren't signed (eg. 7zip, notepad++), so it's not like you're sticking out by not doing so.
- a1369209993 6y ago> If you know how to program, and you can pony up $300 for the code signing certificate, chances are you probably already have the requisite identity paperwork. At a sample size of one (me), this is false in 100% of cases. (To be fair, you did say "chances are" rather than "it is certainly the case that".) > it's no big deal because lots of prominent software aren't signed (eg. 7zip, notepad++) Sure, but that's a argument against code signing in general, not fees versus paperwork.