9 ms·
I feel their pain. I built an open source video player for esports coaches[1] that it given away for free and one the constant complaints about it is that users
by Rodeoclash 3y ago
I feel their pain. I built an open source video player for esports coaches[1] that it given away for free and one the constant complaints about it is that users have to bypass warnings when installing it for the first time.
I can afford to pay for certificates (I believe I have to have one for Windows and OSX) but I refuse to for a project that I already give away my time for.
I would love to see a LetsEncrypt style service for OSS but I assume it's against the core interests of Microsoft / Apple to allow something like this as it would start to drive people away from the walled gardens of the app stores.
I've been writing software for close to 25 years and it's quite sad to watch the decline of ownership over our own machines in the same of "security".
[1] https://www.vodon.gg/ https://www.vodon.gg/
- ikekkdcjkfke 3y agoWhy does an installer need admin rights though
- wetbaby 3y agoI don't think he's saying it requires elevated privileges. When binaries aren't signed Windows will throw up a warning that it isn't signed which makes users hesitant to install.
- system2 3y agoUnrecognized publisher warning in blue box (not UAC) comes up no matter what the software is when trying to install or run.
- Rodeoclash 3y agoThis is correct and it usually takes some combination of right clicking the installer or holding shortcuts to bypass. It's not obvious how to do so without Googling around.
- Kwpolska 3y agoRight clicking is a Mac thing. On Windows, most of the warnings can be bypassed without any special actions (there are two buttons), the SmartScreen warning requires clicking on "More info".
- oefrha 3y agoMoreover, a warning pops up even for signed binaries, until that binary has been installed enough times (?) and Microsoft is satisfied.
- mike_hearn 3y agoNot if you buy an EV certificate. Then you have positive reputation from the start.
- tsimionescu 3y agoHow could it not? It is adding software to the system software set, accessible by all users of the system. And many programs require some kind of integration into the OS, such as file type associations or context menu entries, which even a single user shouldn't have access to do.
- doophus 3y agoMost software installers on Windows offer the user a "Install for this user"/"Install for all users" option, or will just install to the current user's appdata, which doesn't require admin rights.
- pjmlp 3y agoNot the case for ImageMagick, there are some things that cannot be installed for current user, like Windows services or specific kinds of shell extensions.
- tsimionescu 3y agoIt's definitely not "most". It does happen, but it's actually very rare. Most people nowadays who go to the trouble of making a native installer do so because they want some kind of OS integration, so it's a nonstarter anyway.
- Too 3y agoThis way of working should have been left behind in the previous century. Sandboxing should be default. Associating file endings should be a suggestion to the OS, accepted by the user, not something only configurable by delegating full super admin to third party app. Slow loading context menus where every app tries to claim its presence. Thank you for reminding me why I don’t use Windows since years ago. A image editor should only need to load and save images I ask it to, no other system integration. iOS, Android and the browser has proven it is possible. Now the desktop needs a similar journey.
- withinboredom 3y ago> Sandboxing should be default. Please no. There are valid reasons to NOT sandbox, and in Windows there is sandboxing in default (windows store apps) and there are often issues with those versions of the software. For example, Slack downloaded from the windows store uses 30-40% of your CPU while idle, but not when installed from their website. Even in Linux and using the Snap sandbox (ubuntu), there are significant issues when trying to access globally available software, which can be extremely hard to support and diagnose.
- schoen 3y ago> I would love to see a LetsEncrypt style service for OSS but I assume it's against the core interests of Microsoft / Apple to allow something like this as it would start to drive people away from the walled gardens of the app stores. People have been asking Let's Encrypt itself for this on the Let's Encrypt forum since the project was founded. The usual answer is that code signing certificates are (supposedly) trying to attest to a legal identity in the hope of being able to punish people offline if they publish malware, or allow people or organizations to have a policy about only installing software known to be from a certain list of publishers. DV certificates for HTTPS are trying to attest to control of a name in the DNS, which is verifiable by automated technical means, and which is not necessarily related to offline identity. (ICANN says it should be ... in an indirect way ... which isn't always complied with, and which, following increased pressure from European privacy law, is often not visible to the public.) A Let's Encrypt certificate would confirm that a certain key is apparently controlled by someone who apparently also controls a certain DNS name. But a code signing certificate would supposedly go further and confirm that it's apparently controlled by someone acting on behalf of a certain named legal person existing in a certain jurisdiction. This is much more expensive to verify usefully, although maybe some governments will eventually have a way to automate it. This isn't to say that either kind of certificate is necessarily ideal for all of the different uses to which relying parties end up putting it nowadays, but just that what they're attesting to, and how you would verify it, is pretty different. Edit: There seems to be a longer discussion about related points in this thread already at https://news.ycombinator.com/item?id=38056024 https://news.ycombinator.com/item?id=38056024
- leosarev 3y agoI think it would be fine to have code signing certificate ensures that signer controls a certain DNS name. I'm fine with "installer have been signed with somebody who owns imagemagick.org"
- 3c6bYDXLMj 3y agoYes, but most people aren’t. It also significantly reduces the usefulness of code signing for the vast majority. And your justification for that is that it personally wouldn’t be a big deal to you, someone that has an abnormal understanding of the technologies at play.
- Rodeoclash 3y agoAnother pain point with this that I just remembered is that Chrome will also complain about the download if it isn't signed. This does seem to get switched off after enough downloads have been accrued.
- silvestrov 3y agoI think that a main part of LetsEncrypt security comes from renewing the certificate every 3 months. You would not be able to do that with shipped binaries.
- andygeorge 3y agoI mean, you certainly _could_ - most users don't try to regularly reinstall the same binary they downloaded.
- notpushkin 3y agoBinaries are timestamped though. If you sign it, it's practically valid forever (unless you revoke the signature).
- Avamander 3y agoIt takes more than the signing date to assert validity at the time of signing rather than at the time of checking. This means that these signatures tend to expire when the code signing certificate or the CA itself expires.
- electroly 3y agoThat's why you get a timestamp countersignature; that's what the person you're replying to is talking about. They are absolutely correct. This is standard practice. Signed executables on Windows DO NOT lose trust when the certificate expires as long as they are cryptographically timestamped. https://learn.microsoft.com/en-us/windows/win32/seccrypto/time-stamping-authenticode-signatures https://learn.microsoft.com/en-us/windows/win32/seccrypto/ti... My first code signing certificate from long ago is already expired; the signed executables under that certificate are still trusted by Windows.
- hnarn 3y ago> I refuse to for a project that I already give away my time for. Maybe I’m naive but I feel like the solution is pretty obvious: just crowdsource the cost of the certificate and only sign the software as long as the money keeps coming in. If people really do care that much they should be willing to help shoulder the cost, and if they’re not then there shouldn’t be a problem with it being unsigned.
- Rodeoclash 3y agoI don't want to ask for money either. I can afford the code signing, I refuse to pay it out of principle.
- brucethemoose2 3y ago> it's against the core interests of Microsoft / Apple to allow something like this as it would start to drive people away from the walled gardens of the app stores For utility style apps, Microsoft's app store is a joke.
- bigboy12 3y agoWhy the f would anyone use windows with all the hassle, ads, screw overs, tracking and forced hardware updates get a Mac and don’t worry about.
- Rebelgecko 3y agoI dont think any of the games the project lists even work on Mac (CS:GO used to but the latest versions don't)
- WhrRTheBaboons 3y agocool project!
- deleted 3y ago[deleted]