3 ms·
Wouldn’t this be a liability though? In this scenario are you just blindly signing whatever? If yes, that’s obviously not good. The alternative is you have a lo
by safeimp 3y ago
Wouldn’t this be a liability though? In this scenario are you just blindly signing whatever? If yes, that’s obviously not good. The alternative is you have a long review and audit process but in the event something falls through the cracks, this still bites you.
- xrd 3y agoI would be happy to pay for the service. It wouldn't be just the cost of the certificate. It would be the months of labor spent fighting the operating systems and their intricacies. This feels like knowledge that could be managed at scale much better than me doing it in isolation. The cost to me is much greater than just the cost of the certificate, though it's an issue for open source work. And I would be so happy to subsidize that work through a reputable service that was consistent and did that fighting for me.
- Dalewyn 3y agoSeeing as we're now HTTPSing everything under the sun including the malicious, I don't see the problem signing every single binary under the sun regardless malevolence.
- xrd 3y agoAs others have noted on this topic, HTTPS only requires knowing the domain which can be addressed using DNS records. With app signing the operating system vendors want to know you are a legitimate business which means Duns and Bradstreet number and often more, which is much more complicated to validate.