22 ms·
The Windows installer of ImageMagick will no longer be signed
- mg 3y agoIt is interesting, that the lack of a feature that would cost $629 to add is significant enough to make it the the HN front page. Makes me feel like I would like to learn more about open source. What drives it's development and what the business models are. There are 152 contributors to this project who wrote 21,686 commits. If each commit took an hour of work, and we value each hour at $50, that is $1,084,300 worth of time. How can a project gather over a million dollars worth of work time, but not $629 for a certification service?
- _ink_ 3y agoBecause the contributers do the work (the coding) for fun. If they would need to pay $50 so someone else does the work (the fun part) they wouldn't do it.
- mananaysiempre 3y ago(Contributions amounting to $1e6 over 33 years, assuming there is no history-losing VCS migration in the statistics you quoted, and a service that costs $630 per year. While 2% of development cost is still not a lot, it’s not vanishingly small, either.) The economics are probably pretty simple: you can have fun contributing your time to a project, but you can’t have fun contributing money. It’s also easier to get your employer to okay your spending time to upstream bugfixes or even features than to get them to pay money to what’s likely a very vaguely defined organization for a very fuzzily defined service as opposed to straightforwardly buying a thing. (The money itself would be negligible—the accountants’ and lawyers’ time will cost more.)
- uxp8u61q 3y ago> If each commit took an hour of work > we value each hour at $50 If you start with fantasy hypotheses like these, you're going to obtain fantasy conclusions.
- charles_f 3y agoIn this specific case the estimate is likely a vast underestimation of the cost of work.
- xboxnolifes 3y agoThe cost of work is based on the cost of finding someone to do the work. These people did the work for free. This specific work cost $0. The value the work provides may be higher, and I'd wager that ImageMagick has provided far more than $1,000,000 in value.
- throwawaaarrgh 3y ago> Makes me feel like I would like to learn more about open source. What drives it's development and what the business models are. Simple: there is no business model. Open Source is not a business. It is a philosophy and hobby, where people help each other and give away their labor with no expectation of a return. (Some youngsters that have grown up in the social media age have developed a kind of entitlement complex where they focus more on the popularity of their contribution than its utility; they may be developing it just to see a lot of stars on a GitHub page. But largely it's a community driven by people who just needed some code to exist and then released it for free when it worked) (Some businesses do release code with an open source license and even accept some contributions from the public, but largely they are doing so for various business reasons and the project is more a reflection of the business than the needs of a community. Since those projects are financed and organized by the business, they tend to end when the business abandons them; whereas a grassroots community project is often just maintained by a new stranger on the internet if the old maintainer gives it up)
- andyfleming 3y agoI'm not sure whether or not there's an issue of entitlement, but there's certainly incentives to develop a popular package (even if superficially). One big one is career development. For people early in their career, it's something they can proactively invest in, as where they can't magically materialize years of experience overnight.
- Dalewyn 3y agoThere is definitely an argument to be made that open source should be viewed and treated as a business model, particularly if there are financial costs involved which must be paid one way or another. Dogma and fervor don't pay the bills.
- alkonaut 3y agoStill, high profile projects should be able to raise this type of money with ease. If they would say “Would match our ‘donation’ and donate $10 each year that we put in $1k in labor to this project?” that sounds like some commercial users would accept. But the first problem with medium scale OSS like this is that it’s no one’s hobby to manage projects or beg for money. It’s also a problem that OSS contribution/sponsorship isn’t normalized in corporations. I could much easier get permission to buy a $5k piece of software than donate $5 to an OSS project that powers out largest project and has been maintained for 10 years by a single person.
- smokel 3y agoBy that logic, reading a classic novel such as Anna Karenina would set you back $720. [1] [1] https://www.readinglength.com/book/isbn-0143035002 https://www.readinglength.com/book/isbn-0143035002
- rtpg 3y agoThe classic thing is that "nobody uses Windows". The real thing of course is that many people contributing to various projects end up using some *nix setup. So despite Windows being a big part of many userbases, ultimately maintainers often don't even have a Windows machine, let alone the knowledge to deal with some Windows-specific issues or bugs. Though here it seems to be mostly a money thing ($629/year is a real amount of "pocket change").
- a1369209993 3y ago> How can a project gather over a million dollars worth of work time, but not $629 for a certification service? Because the certification 'service' is a protection racket (as in criminal[0] racketeering) by Microsoft. Millions for defence (or in this case infrastucture), but not a cent for tribute. 0: Since I'm sure some pedant will nitpick this: yes, I'm aware that large corporations have likely purchased legislation misclassifying this as not officially a crime; you know perfectly well what I mean.
- deleted 3y ago[deleted]
- nwellinghoff 3y agoIt’s principle. A fundamental of the hacker mentality. A hacker will jump through hoops to do something based on principle. Something others legitimately have a hard time understanding. That being said why the HELL is it 629 dollars!?
- deleted 3y ago[deleted]
- woodruffw 3y agoThis might be a misunderstanding on my part, but why does the ImageMagick code-signing certificate need to meet CA/B Forum requirements? My understanding is that those requirements apply primarily to the Web PKI, and not other PKIs or certificate profiles like Authenticode. (Regardless, vendor-specific code-signing schemes are a racket.)
- stop50 3y agoThere is no institution like the CA/B Forum. Everyone uses their certs.
- woodruffw 3y agoThere are plenty of other certificate profiles besides CABF, but that’s besides the point. My actual question was whether Autheticode is actually requiring the CABF BRs for OV certificates, or whether there was some arbitrary CA-side policy change.
- mike_hearn 3y agoYes CA/B Forum sets policies for Windows code signing certs and CAs just follow, even in cases where it's harmful to their customers or obviously dysfunctional :( CA/B Forum and its members are ignored by Apple and for good reasons. They run their own PKI which is a lot easier to use and cheaper.
- Avamander 3y agoGood reasons, such as? Actually trying to mandate some sort of secure storage is not a "good reason"? Have you not read about how many of those keys have been stolen and abused?
- mike_hearn 3y agoI'm well aware! It's actually Microsoft that originally pushed for that change, CA/B Forum just implemented it IIRC. Apple's PKI: 1. Has a much easier verification process. 2. Is a lot cheaper, dev program membership is ~$100/yr and they throw in a couple of DTS incidents as well. 3. A big one: Apple's PKI issues certificates with long term stable identifiers (team IDs). CA/B PKI specifies all kinds of random details that CAs have to follow but the subject name isn't one of those, so systems that use the subject name as a key (which Windows does in various places) will immediately forget who you are if you change to a competing CA, or change your company name, or it relocates its HQ, or if you change OV<->EV, or if they just change their policies again for no real reason. This problem makes CA/B certificates largely useless in practice because you can't associate anything with the verified identity. They know this problem exists because I have raised it with them specifically, and they don't care. 5. The root and intermediates are more stable (experience odd expiration/cross signing issues less or not at all). 6. Apple hardware can protect private keys using the secure element that comes with the device, so it can have equivalent security without needing the USB token. USB tokens have a bunch of issues. Also Apple's OS can limit those hardware protected keys to specific bits of software too, so you can ensure that only your code signing tool or build process can access the key. USB dongles can't do this, anything that can talk USB and get your credential can use it. So those are some specific technical justifications for you.
- DaiPlusPlus 3y agoI"m curious what the actual negative impact of this would be - ImageMagick is a command-line tool (or runs in-proc somehow) and rarely used directly by end-users, just like LAME and ffmpeg - and the binaries are far more often shipped as part of another application. My day-job SaaS uses ImageMagick on Windows (long story), but this doesn't affect us - I imagine most other users will be the same. I'm surprised they even make an installer for Windows at-all instead of only shipping portable zips.
- jabroni_salad 3y agoSome PDF-related apps used to bundle ghostscript's installer as a silent install and it would just appear in your programs list. Then those users would see a mysterous entity named ghostscript in their start menu and complain online about it being malware or whatever. The ghostscript people decided to disable their silent installer because of it. The fallout has been that corpos can build it from their source and ship it themselves if they need it so bad, and users are always informed up front about what is coming to their computers. Let that stick in your brain for next time you wonder why Windows still hasn't gotten a competent package manager that can wrangle dependencies. The userbase has been made terminally paranoid by decades of trojans and adware installers.
- DaiPlusPlus 3y ago> Let that stick in your brain for next time you wonder why Windows still hasn't gotten a competent package manager that can wrangle dependencies. winget?
- gary_0 3y agoWe need a LetsEncrypt for executable signing. Although I suspect Microsoft and Apple are making distributing executables for their platforms costly and inconvenient on purpose in order to drive developers onto their app stores. If that's the case, I guess we'll just have to train users to ignore all the security prompts about unsigned installers (some developers already do).
- woodruffw 3y agoThat’s the idea behind Sigstore[1]. The larger challenge is the vendors themselves: Sigstore (or anyone else, really) can give code-signing certificates and tooling to developers for free, but that tooling has limited value if the host OS doesn’t bundle the CA certificates that would enable native validation. [1]: https://www.sigstore.dev/ https://www.sigstore.dev/
- uxp8u61q 3y agoWait, their certificates aren't trusted by the os? What's the point of their service, then? A self-signed certificate accomplishes the same result!
- woodruffw 3y agoThere are lots of systems (and ecosystems) where host trust doesn’t matter, like containers or language-specific package management. Sigstore is currently well-suited for those contexts. With a self-signed certificate, you are effectively your own PKI. The goal is generally to deduplicate that kind of work while also providing better security properties than “my host trusts self-signed certificates from a root CA that I keep on disk somewhere.”
- fragmede 3y agoWell the assumption is that the root CA stores them more safely than "on my laptop in my unlocked bedroom in an unassuming neighborhood of brighton" that most developers lean on for their secret storage, but, well, you never know.
- ImAnAmateur 3y agoAny opinions on this tool? I've literally never heard of it before. Seems like it's good for simple bulk editing.
- throwawaaarrgh 3y agoImageMagick is the most widely used open source image processing library and tool in the world. The source code kinda sucks but it does everything you could want, pretty much
- fodkodrasz 3y agoIt is a common source of security vulnerabilities. Also the API is has silly names, uses globals, not really nice, and not really FFI friendly (overcomplicated). Also requires global installation, cannot be deployed side by side with projects. For me it is a solid red flag for any project if they are using ImageMagick/GraphicsMagic. I don't let it near my computers.
- withinboredom 3y agoToo bad it is already there...
- fodkodrasz 3y agoWhat? Where?
- teddyh 3y agoWhat do you use, then? Netpbm?
- fodkodrasz 3y agoDepends. libgd (has good API for FFI, van be side by side installed easily). ImageSharp (C#, very good, paid for commercial use). Sharp (JS). I use hugo's build in image tools. Sometimes a desktop app: Paint.Net. Affinity Photo. Whatever else suits my needs.
- throwawaaarrgh 3y agoMaybe someone can start signing a Windows release of GraphicsMagick? http://www.graphicsmagick.org/index.html http://www.graphicsmagick.org/index.html Also FYI, Bob is pleading for some volunteers to help manage the project; he's doing it all on his own as a side project. If you can, please put the word out
- 01100011 3y agoInteresting. I tried to remove imagemagick from Ubuntu 22.04 but it is depended upon by inkscape, calibre and pdfsandwich. I wonder if it's possible for these projects to use GM instead?
- jimmySixDOF 3y agoI am not sure I get the difference between these projects and have trie, also looked at libvips, but for me with a narrow use case of batch overlay text insertion I could not find anything.
- jcupitt 3y agoWe're off topic here, but in pyvips (for example) you can do text overlays like this: https://github.com/libvips/pyvips/blob/master/examples/annotate-animation.py https://github.com/libvips/pyvips/blob/master/examples/annot... tldr: make an image containing your text, composite it over the image you want to annotate.
- technion 3y agoJust throwing in that the dollar value isn't the only cost. I've been using an automated release workflow tomanage signing, eg https://github.com/technion/rustypwneddownloader/blob/main/.github/workflows/release.yml https://github.com/technion/rustypwneddownloader/blob/main/.... This worfklow isn't usable with these new rules, and I'm having a hard time with the assertion that moving builds to my desktop to use a hardware signing key and uploading them in a non automated, non transparent fashion is an improvement on security.
- electroly 3y agoI'm in exactly the same boat; doing the same thing to store my OV .pfx certificate in a GitHub Actions secret. My certificate expires in November 2024 and I'm undecided what I'll do. It was hard enough to get a certificate as a solo developer and not a corporation. Still, though, it should just be a matter of money. The $629/year cloud-hosted HSM mentioned in the OP will do it. If you pay that, you can use this procedure to make it work with GitHub Actions with the same sort of signtool or Set-AuthenticodeSignature command that you use now: https://docs.digicert.com/en/software-trust-manager/ci-cd-integrations/plugins/github-custom-action-for-keypair-signing.html https://docs.digicert.com/en/software-trust-manager/ci-cd-in...
- jborean93 3y agoI’ve found the easiest option available here is through using Azure KeyVault to store the keys. I use a custom module to sign my PowerShell scripts and dlls [1] for this because I can integrate it with OIDC to sign the code using the keys stored in the Azure HSM. While the builtin pwsh Set-Authenticode cmdlet can’t do this currently there are other options that rely on Window’s authenticode APIs like AzureSignTool [2] that I highly recommend. While I’m unsure if Azure is suitable for actual companies I think the risk is ok for what I need it for and the API quality as well as OIDC support make it quite nice to use with GHA. [1] https://github.com/jborean93/PowerShell-OpenAuthenticode https://github.com/jborean93/PowerShell-OpenAuthenticode [2] https://github.com/vcsjones/AzureSignTool https://github.com/vcsjones/AzureSignTool
- 3y ago
- snnn 3y agoCompare to codesign, vulnerability management is more concerning. Ubuntu users should know that security patches for ImageMagick are not free! If you do not believe that, read this https://ubuntu.com/security/notices/USN-6393-1 https://ubuntu.com/security/notices/USN-6393-1. The security patch is only provided through Ubuntu's Expanded Security Maintenance (ESM) plan, which means you must pay for it. So, seriously, consider having you own build. Then there is no need to worry about codesign too.
- r4indeer 3y agoWhat does this have to do with ImageMagick? They don't control the versions packaged by Canonical [0]. The bug you referenced is fixed in upstream, which you can access for free on GitHub. Ubuntu users on 22.04 LTS or later are also unaffected, because the release came with a version that was already patched [1]. If you upgrade to a newer Ubuntu release, there is no need to pay for ESM. Your comment makes it sound like the ImageMagick developers want money specifically from Ubuntu users to reveive security patches, which is not true. [0] https://github.com/ImageMagick/ImageMagick/discussions/6805#discussioncomment-7330725 https://github.com/ImageMagick/ImageMagick/discussions/6805#... [1] https://ubuntu.com/security/CVE-2022-48541 https://ubuntu.com/security/CVE-2022-48541 Edited to add some links.
- 1letterunixname 3y agoYou appear to be leaping to the wrong conclusion. The problem is Canonical charging money for security updates. CentOS, Alma, Rocky, Fedora, Debian, openSUSE, Arch, and 300+ other Linux distros don't charge money for security updates either. The moral of the story is "Don't use enshitifying corporate Linux distros run by crazy people."
- r4indeer 3y agoThis still has nothing to do with the ImageMagick developers, which the original comment implies: "Compare [sic] to codesign, vulnerability management is more concerning." You are free to criticize Canonical for their business model, but that seems off-topic to me right now.
- Rodeoclash 3y agoI feel their pain. I built an open source video player for esports coaches[1] that it given away for free and one the constant complaints about it is that users have to bypass warnings when installing it for the first time. I can afford to pay for certificates (I believe I have to have one for Windows and OSX) but I refuse to for a project that I already give away my time for. I would love to see a LetsEncrypt style service for OSS but I assume it's against the core interests of Microsoft / Apple to allow something like this as it would start to drive people away from the walled gardens of the app stores. I've been writing software for close to 25 years and it's quite sad to watch the decline of ownership over our own machines in the same of "security". [1] https://www.vodon.gg/ https://www.vodon.gg/
- ikekkdcjkfke 3y agoWhy does an installer need admin rights though
- wetbaby 3y agoI don't think he's saying it requires elevated privileges. When binaries aren't signed Windows will throw up a warning that it isn't signed which makes users hesitant to install.
- system2 3y agoUnrecognized publisher warning in blue box (not UAC) comes up no matter what the software is when trying to install or run.
- Rodeoclash 3y agoThis is correct and it usually takes some combination of right clicking the installer or holding shortcuts to bypass. It's not obvious how to do so without Googling around.
- Kwpolska 3y agoRight clicking is a Mac thing. On Windows, most of the warnings can be bypassed without any special actions (there are two buttons), the SmartScreen warning requires clicking on "More info".
- umvi 3y agoSeems like security is slowly eating the software world. At some point security will be so onerous that it will take more effort than the actual software being secured. Software was more fun in the good old days before there was a huge criminal industry exploiting it. Alas, it was bound to happen eventually. That said, seems like you could bring down that price by hosting the key yourself with a yubikey or cloud hsm instead of buying the turn key solution from digicert.
- rivepica 3y agoThe issue here is the high financial burden to have a secure/signed release, not the security itself.
- dwattttt 3y agoI always assumed it wasn't the cost per say that provided value; malware authors certainly could lay hands to $630. The value is in actually asserting authorship & tying it to a legal identity. I'd assume creating a fake persona / faking whatever is required to satisfy the identity checks that come with that $630 is the actual deterrent. If it was cheap to perform the actual identity checks it would still provide this effect.
- TeMPOraL 3y agoAnd arguably the issue also isn't with money - it's that the value in "actually asserting authorship & tying it to a legal identity" is primarily a value for commercial vendors and platform owners. It's forcing open source developers to entangle themselves in the very system that open source culture is (or was) fundamentally in opposition to.
- criddell 3y agoHigh financial burden? It’s something like $600. For me, the tragedy is that something as useful and valuable as ImageMagick is scraping by with so little support from end users and other companies and projects that use it.
- deleted 3y ago
- Ayesh 3y agoNow that GitHub has CI and MSFT money, it would make so much sense for GitHub to become a code signing CA! With npm, you can opt in to have your npm package releases signed, and it took less than five minutes for me to integrate. As long as the package is published with GitHub Actions (or other supported CIs I guess), you can sign the package and npmjs shows it as well. Git also has release and commit signing with gpg/ssh keys, so the authentication is already solved. https://github.blog/2023-04-19-introducing-npm-package-provenance/ https://github.blog/2023-04-19-introducing-npm-package-prove...
- ikekkdcjkfke 3y agoThat's still a single point of failure, so the signing doesn't provide any extra security
- woodruffw 3y agoAll PKI schemes have multiple singular points of failure: the user and system trust stores, the root CAs, the end-entity certificate, the security of all hosts, &c. Singular points of failure aren’t inherently an issue; the bigger concern is how strong each point is.
- toastal 3y agoSounds like Microsoft… you get Microsoft npm releases signed if you use Microsoft GitHub Actions. Deployed to Microsoft Azure, built with Microsoft GitHub Codespaces enhanced with Microsoft GitHub Copilot, all from your Microsoft Windows machine. Folks shouldn’t be forced to use proprietary software from US-based, publicly-traded megacorporotations just to build & sign their libre software.
- charcircuit 3y agoThese code certs verify the orginization who created the executable. Those are not the same guarentees as a signature for a commit.
- Too 3y ago
- theanonymousone 3y agoLet's normalise using WSL for all such command-line utilities. Everyone's life will be easier, from developrs to users.
- toastal 3y agoSkip the ‘WS’ part & just use the ‘L’
- pjmlp 3y agoThe Year of Desktop Linux is around the corner!
- J_Shelby_J 3y agoYes. They’re called Codespaces.
- quickthrower2 3y agoWith some GNU too!
- pjmlp 3y agoWindows developers are perfectly fine without WSL. WSL is meant for UNIX developers to bring their habits into non-UNIX OS, just like IBM mainframes and micros have PASE.
- vkazanov 3y ago
- atesti 3y agoHow does this work? Does Digicert "host" the HSM in the cloud for you and make it possible to automate things again? The goal of us developers is of course to fully automatically sign an executable, while the CAB forum seems to want one to always enter a pin code in a hw device anytime you make a build. Are there any good solutions or hacks to automate it? Does Digicert really make it possible again to just invoke signing of anything from the command line or CI task WITHOUT entering any pin or 2factor stuff? That would be great, and of course ultimately circumvent the CAB forum's demands as anyone who stole the digicert credentials can now sign anything.
- mike_hearn 3y agoThe cheaper option is SSL.com eSigner which is also a cloud hosted HSM where you can access it using ordinary saved credentials. In theory they want you to use a 2FA authenticator for it so their protocol requires TOTP secrets and the like. In practice nothing stops you saving the seed to a file, so you can sign automatically. Of course then you're reducing the security gained by the system. Your CI becomes a very weak point. But it does work. The CAB Forum is well aware that people want to and can sign automatically. The purpose of the HSM is to fix revocation, not to require manual intervention for signing software.
- keepamovin 3y agoIt’s astonishing that a project as critical and widely used as ImageMagick can’t even scrape together $629 for something as essential as a software signature. It’s a glaring example of how the tech industry fails to financially support the very open-source projects that it relies so heavily upon. Despite offering incredible value, these projects often can’t capture enough of it to sustain themselves. It’s a sobering reminder that something significant needs to change in how we approach and value open-source contributions.
- rand846633 3y agoIt’s also not clear why the IM project should be paying MS and not the other way round…
- lodovic 3y agoBut that's a thin line. Free certificates negate security. Instead, there are various foundations that sponsor popular open source projects for costs like signing certificates and hosting. I'm sure one of these should be trustworthy enough to obtain a signing certificate themselves so they can issue and revoke certs to various projects without much cost.
- sime2009 3y agoLook at it this way, why should a project like IM pay MicroSoft for the privilege of enriching and adding value to the Windows platform?
- 1letterunixname 3y agoLack of open governance explains the fork in 2002. [0] The github commit history shows it's still a largely one-person-band. [1] The problems with this include a lack of succession planning, a lack of ability to scale bandwidth, and a narrower pool of ideas. The documentation website is really out-of-date as it mentions using a Borland compiler. Alternatives to IM: - https://www.libvips.org https://www.libvips.org - http://www.graphicsmagick.org http://www.graphicsmagick.org (IM fork) 0. https://marc.info/?l=imagemagick-developer&m=104777007831767&w=2 https://marc.info/?l=imagemagick-developer&m=104777007831767... 1. https://github.com/ImageMagick/ImageMagick https://github.com/ImageMagick/ImageMagick
- justinclift 3y agoHas anyone here tried out that SignPath (https://signpath.org https://signpath.org) thing mentioned in one of the responses? From their website: SignPath Foundation provides reliable code signing for Open Source projects. If it's legit, then it could be a useful option.
- orra 3y agoIt appears legit, in that vim and transmission link back to it. Right now the "foundation" is run by the SignPath company. But TBF they say they hope the foundation will eventually scale, and become independent and community run.
- mikewarot 3y agoWhy do we let any random application open its own files and folders at will? The actual selection and opening of files and other resources should be the job of the operating system. GUI programs should be able to call "open" "save" and other dialogs to get handles to files, not just their names. The OS should limit access to resources to those it provides (as capability tokens) and nothing else. For CLI programs, the shell should take care of managing parameters in a standard and trustable way, also returning tokens instead of file names. Collectively, we're like chicken caught out in a rainstorm... looking up, frozen in panic. Some of us know how to get out of the rain... but we're stuck in the middle of the flock.
- vbezhenar 3y agoBecause we're using operating systems rooting from 80-s and nobody's going to rewrite them from the scratch along with all the software running on top of them. Web applications are the best thing we could get.
- TeMPOraL 3y agoWell, if Ubuntu Snaps are any indication, then I'm happy for the 1980s OS design. I mean, it's cool that you can get a sandboxed program with simple CLI comamnd. It sucks that it's completely useless until you figure out how to give it access to the host file system, because guess what, most software that's useful for anything other than entertainment needs to interoperate with other software using files. To be fair, Android does it better in that at least the apps can call into system file picker, which lets me simultaneously navigate the host FS and grant the app access to specific files or folders (and it explains what it's doing). Still, I'm worried, because decisions about future OS and platform architectures are increasingly made by people who grew up in the "apps era", and likely internalized the misguided idea that "data produced by a program belongs to that program", further disempowering the users (including, ultimately, themselves). This is in opposition to the idea that made computing ubiquitous and a tool for people to improve their lives: the idea that data is independent of the software that produced it; that the data files are owned by the user, can be copied and moved around using generic means, and worked on in many different software tools.
- thangalin 3y agoMy desktop text editor, KeenWrite, uses Wine, rcedit-x64.exe, osslsigncode, and a shell script to sign the Windows binary. First, rcedit-x64.exe tags the binary with identifying information: https://gitlab.com/DaveJarvis/KeenWrite/-/blob/main/installer.sh?ref_type=heads#L200 https://gitlab.com/DaveJarvis/KeenWrite/-/blob/main/installe... Then osslsigncode applies the certificate: https://gitlab.com/DaveJarvis/KeenWrite/-/blob/main/scripts/sign.sh https://gitlab.com/DaveJarvis/KeenWrite/-/blob/main/scripts/... Echoing what Rodeoclash wrote: Having to pay to play on Windows for an open-source project that makes $0 is a decline of ownership over our own machines.
- veeti 3y agoAs a heads up you are not going to be able to renew your certificate for this, it needs to be HSM backed now.
- matharmin 3y agoI recently went through this same issue at my company - only found out about the change in requirements when I couldn't renew my cert at the previous provider. There is surprisingly little info available on how to do code signing for Windows now. I don't want to use a physical device - with fully remote teams it's not feasible. Eventually settled on Azure KeyVault with Digicert (I don't like Comodo aka Sectigo). There is really little info available on how to get it all to work together, and you have to spent around $600 before you can even try and see whether it can work. Now that it's all configured, the setup works well. The new setup of doing the signing via Azure is more secure than storing the private keys on the CI system. But I never thought that signing an app for Windows would be more difficult than signing for macOS or iOS.
- alkonaut 3y agoI’m thinking that it might be by design that it’s somewhat hard and expensive.
- kuzko_topia 3y agoHey, is there any chance you could do a writeup on how you did things? due to the lack of information you mention, I think it might be useful for a lot of people there, including me.
- mike_hearn 3y agoIt's not the way the OP did it, but there's a blog post here on how to ship apps using cloud signing with the Conveyor tool. The title talks about Electron but it should work for any kind of app (not tested with .net) https://hydraulic.dev/blog/21-shipping-electron-apps-from-ci-using-hsm-certificates.html https://hydraulic.dev/blog/21-shipping-electron-apps-from-ci...
- matharmin 3y agoI'm probably not gonna get to a full post anytime soon, but I'll summarize here. This is from memory, so I may have some things wrong. 1. DigiCert CS certificate. You can validate your organization before paying anything, but it felt like we ended up in a low-priority queue because of that. After not hearing back for 2-3 weeks, I emailed support, then got validated in a day or two. 2. Azure KeyVault: "Premium" pricing model, since you need RSA 3072-bit or RSA 4096-bit HSM-backed keys. Generate a CSR here. There are a couple of annoying steps such as getting the access control setup right, but nothing too complicated. 3. Once you have a validated org and paid for the CS certificate, you can upload the CSR to DigiCert, and download the certificate. 4. "Merge" the certificate on Azure KeyVault. 5. Create an "application" on Azure which gives you API credentials. You need to copy a whole bunch of IDs: # key vault: azure-key-vault-url azure-key-vault-certificate # client application: azure-key-vault-tenant-id azure-key-vault-client-id azure-key-vault-client-secret You use the above with AzureSignTool to do the signing, e.g. from you CI system.
- nolist_policy 3y agoYet another reason to go with web apps/electron. The electron binary is already signed. And Web apps are good with a Letsencrypt cert.
- geraldcombs 3y agoHow are Electron apps typically shipped? If the answer is "inside an installer" then the installer needs to be signed.
- alkonaut 3y agoThese days in 99 cases of 100 I’d use something like Sqirrel to install per-user and enable self updates. But it’s still and executable and I still think Windows Defender will react poorly to an unsigned one even if it isn’t going to need any elevated privileges.
- breakfastduck 3y agoDepends on the target platform. For macOS for example it's just the '.app' bundle.
- donatj 3y agoI really wish they would lower the cost of signing certificates generally. $10 tops. I can’t justify the cost for my very specialized software very few people use. My only explanation for why it needs to be so expensive is that it needs to be a large enough charge that the rightful owner of a stolen credit card might notice it? Because it’s in and of itself an author verification? If that’s the case though, they could refund some or all of it after say 3 months? Even then, just as a verification, there seems like very little need to charge for that verification annually. It really just seems like rent seeking.
- mike_hearn 3y agoMicrosoft have lowered it. The store costs $19 iirc, one off fee, not recurring or yearly. So this is only for distributing outside their store. Certificates are expensive because governments aren't digitized and don't really "do" cryptography, so associating ownership of a private key with ownership of a legal identity requires a lot of manual effort. CAs have to do things like look up your registration details in country-specific websites that don't have APIs, make phone calls, study passport scans and so on. That's all very labor intensive which makes it expensive. It could be made a lot cheaper if governments ran their own PKIs and issued every company registrant with private keys as part of setup, likewise if passports came with private keys usable for document signing (govs already run PKIs for e-Passports but you have no way to associate a personal private key with that certificate). Unfortunately there's been no movement on that for a long time, and the few countries that did experiment with national PKIs have mostly given up. America never tried to do large scale government PKI outside of the DoD, and therefore US software firms never felt much need to do a good job of smartcard support. No mainstream operating system has solid support for it, standards are lacking, etc. Then you have the generally high overheads that the certificate consumers (Microsoft) and CA/Browser forum mandates for CAs. That costs money too. Then the overheads that come with a company existing at all (websites, taxes, salaries etc). The reason for the annual fee is to amortize the cost over time. It costs the CA more than the 1-year fee to issue the certificate in the first place, but if they assume you'll use it for at least a few years then they can break even then make a small profit.
- Reason077 3y ago> ”Digicert seems to be our only option now but a certificate there would cost $629 (tax excluded) for a single year.” Yikes! At least Mac (and iOS) developers get this for $99/year. What makes code signing so expensive on Windows?
- iforgotpassword 3y agoGreed
- deleted 3y ago[deleted]
- draw_down 3y ago[dead]
- kaetemi 3y agoA basic code signing cert can be had at $150 per year. That's already with the thing where they check if your company information is real, and it does the job for SmartScreen. Not sure if there's any advantage in the more expensive ones.
- tzs 3y agoThe $629/year is if they use a certificate from one particular company (Digicert) that manages keys in a way that would be easiest for them to fit into their current workflow. There are other options that would require more changes to their workflow but are much less expensive. See the responses on GitHub or the other comments here for several of them.
- jacquesm 3y agoSo much for 'Developers, developers, developers!'. If there is one thing that seems to be common amongst large tech companies it is that it all starts out looking great, then after a few years the rot sets in and if they manage to hang on long enough eventually they turn into parasitic entities. There is no way that a company the size of Microsoft could not come up with a way of working that would enable the FOSS world that they claim to be such huge supporters of to deploy on their platform without hassle or cost. All of this friction in the name of security always accidentally helps the bottom line.
- keepamovin 3y agoWell said!
- andygeorge 3y agoAgreed. That said - and maybe I'm missing something - but why did did ImageMagick wait til the _day of expiration_ to make this post?!
- sambeau 3y agoThere are some open source technologies keeping the internet-as-we-know-it alive. Surely the might of Github and Microsoft could support them or, even better, a consortia of the Big Tech companies could get together a comittee, like they often do for standards, and agree to fund the most used open source projects with stipends, grants, security audits and some sort of badge of trustability.
- Kim_Bruning 3y agohttps://www.gnu.org/philosophy/right-to-read.en.html https://www.gnu.org/philosophy/right-to-read.en.html The longer I live, the more I realize RMS is a modern Cassandra.
- joelthelion 3y agoSounds like something GitHub themselves could fairly easily offer.
- xrd 3y agoI've been through hell and back on both Windows and MacOS with application signing. It's only getting worse. First thing I have to note is that this really makes me want to offer anything as a web app. The browser offers a much better experience in so many ways and security is a well thought out integrated experience unlike these 25 year old operating systems bolting security on as an after thought. Clearly no one at Apple cares about this but that would be funny if this was the crack in the dam that broke down their hardware software monopoly. Second thing is why can't a third party offer this as a service? I'm not limited in the number of apps I can sign technically, right? Why would people using my app care that the certificate says it is signed by me instead of (trusted by the os) ABC, corp that (Microsoft|Apple) says in their overlaid dialog they trust. They could revoke something in the chain but it's technically possible right? Is this explicitly prohibited in some EULA I accepted in a brain fog?
- safeimp 3y agoWouldn’t this be a liability though? In this scenario are you just blindly signing whatever? If yes, that’s obviously not good. The alternative is you have a long review and audit process but in the event something falls through the cracks, this still bites you.
- xrd 3y agoI would be happy to pay for the service. It wouldn't be just the cost of the certificate. It would be the months of labor spent fighting the operating systems and their intricacies. This feels like knowledge that could be managed at scale much better than me doing it in isolation. The cost to me is much greater than just the cost of the certificate, though it's an issue for open source work. And I would be so happy to subsidize that work through a reputable service that was consistent and did that fighting for me.
- Dalewyn 3y agoSeeing as we're now HTTPSing everything under the sun including the malicious, I don't see the problem signing every single binary under the sun regardless malevolence.
- whywhywhywhy 3y agoI ship a piece of free macOS software based on pyinstaller. Literally include a script to bypass the signing for the entire folder to get around having to pay. It’s bad practice. Confusing for users and dangerous for users to get used to doing something like that. But yeah I’m not paying $99 a year.
- butz 3y agoWith ffmpeg running straight in the browser, maybe ImageMagick could go that way too for systems requiring signing? In the end developers might take a second look at more open alternative OS.
- wiktor-k 3y agoI had the same problem and ended up buying Certum Open Source set for 69 EUR: https://shop.certum.eu/open-source-code-signing.html https://shop.certum.eu/open-source-code-signing.html The set does include hardware token for storing the private key as well as a certificate valid for one year. Renewal is 25 EUR. It does require verifying identity with government issued ID though. I haven't seen anything cheaper on the market (happy to hear suggestions).
- MilStdJunkie 3y agoI'm not a super gee-whiz technical guy, but what exactly are you getting out of a windows installer vs *.exe + ENV variables? I personally prefer software that just runs as packaged executable, and I can add system variables either at launch or by myself. It's always a little sus when a tool doesn't have a portable release. It's sort of my secret solution to using software I need from gimped userland, although I know it lights alarms in the big InfoSec secret dungeon. Luckily, they're lights for "Visual Studio Code", so that "alarm" is on all the time.
- thenerdhead 3y agoThere is a solution here but nobody knows about it. https://www.youtube.com/watch?v=Wi-4WdpKm5E https://www.youtube.com/watch?v=Wi-4WdpKm5E Also it has been 3 years since that video and even a modern search still has unclear messaging if this thing is even an option to be used today. Looks like a dev commented in the GitHub issue, but clearly the maintainer of this project had no idea it existed.
- Zuiii 3y agoYou can use the embedable release of python (which is signed) to run arbitrary unsigned code on windows. If you don't believe me, try it. Code signing on windows is a security theater at best and is next to useless. I agree that let's encrypt should just issue them. If Microsoft refuses to support it, someone should write a windows kernel module to add (or patch in) support.
- gloosx 3y agoThe certificate process at Microsoft is an absolute hell designed for their "authorized" sales people to generate money out of thin air. As a result – most people now skip the "SmartScreen" warning at the level of habit. This warning just adds to the noise from the Windows system which you want to skip as fast as possible. Tons of good software simply can't afford it or won't bother getting such a non-portable thing as hardware FIPS. Classic Microsoft "just shove it up your throat" practices for the sole purpose of revenue
- winwhiz 3y agoI'm not trying to be snarky and now I can't even remember where I heard it... but aren't all of Microsoft's keys still flapping in the wind themselves? Thanks to the work of some state actor?