3 ms·
"It sure would be a shame if we went around telling people your program is a virus. We can make sure that doesn't happen, if you pull out your credit card and
by csense 3y ago
"It sure would be a shame if we went around telling people your program is a virus. We can make sure that doesn't happen, if you pull out your credit card and pay us a three-figure sum."
A financially lucrative but morally bankrupt business model. It's basically a 21st century twist on an old fashioned protection racket.
- NoZebra120vClip 3y agoOn the flipside, a financial barrier to entry is one of the most effective ways for us to ensure legitimacy. If it is $FREE (and I mean no credit card, no identifiable payment information, etc.) to obtain digital signatures and get past the gatekeepers, there is no other meaningful barrier that can't be sidestepped or overcome by clever effort. Demanding payment for any service is a pretty good way to ensure that some valuable fraud indicators are available in the transaction. If you are a stranger and you've produced a bit of code you're enticing me to run on my computer, then you are, by default, going to be flagged as a virus, and that is in my best interest. This isn't 1993 anymore; we can't trust shareware authors not to be Russian virus authors. So I don't see how it's a "protection racket" to go zero-trust architecture and say that anything legitimate needs to bear all the hallmarks of legitimacy, or it doesn't play on consumer equipment. Sure, yes, of course, this hurts the little guys who are also legit, and it doesn't stop threat actors with deep pockets, but it does serve to sift out the small-time scammers who are constantly pounding at your door and definitely finding ways in.
- csense 3y agoI've never used code signing, and I'm not really sure how it works. Do you need to submit your source code or binaries to the signing organization? How are they checked? How is code signing supposed to prevent Eve from just paying for a cert, then writing a program that steals your data or crypto ransomware? What if Eve pays with a prepaid debit card or a stolen credit card?