Windows gifski.exe with a digital signature
github.com
github.com
I was incredibly salty about this. I didn't name the CA, because they're actually nice to have reduced price for Open Source projects, but Microsoft really needs to drag the whole process into the 21st century.
The process and infrastructure reminds me very much of TLS before Let's Encrypt. If this is something that every developer needs to do for every exe, it can't be like getting an EV certificate for a Netscape Server. I thought Apple's often-buggy signing was bad, but at least they've tried to make it a one checkbox paid for in a straightforward transaction.
I would have signed with SHA-2, which for inexplicable reason is not the default despite deprecation, but my signtool crashed when I enabled it.
signtool sign /a /fd SHA256 /tr "http://timestamp.globalsign.com/?signature=sha2" /td SHA256 <exefile>
And maybe I'm spoiled, but could it not require four switches of a "don't do useless thing" kind? It's as if `copy` required /ones /zeros switches to be explicit you don't want it to omit these bits.
That said, I just upgraded ours and didn't have much trouble switching to sha256. There is one quirk about the order of the arguments due to some limitation with the timestamping servers. The documentation loudly points this out though. If it helps, here's my exact command line:
signtool.exe
sign /v
/n "Company, LLC"
/ph /d "Description"
/du "https://www.website.com"
/tr "http://timestamp.comodoca.com"
/td sha256 # /td must come after /tr
/fd sha256
executable.exe
Not being able to automate these EV hardware tokens because of the password is a pain that I'm already annoyed by though.I believe you can use mimikatz to forcibly strip the strong protection flag from the key. Microsoft says this is normally not possible, yet here we are. You might want to try downgrading the strong protection flag on the key material, it may allow for automated signing.
Confirmed HTML
We've basically got a giant keystore server that handles the secret keys for all of the company's signing, then signing provider plugins installed on the build machines to communicate with the keystore, while allowing us to use standard tools like signtool.
Just remember to timestamp while you sign!
In one example, the provider needed to check I was a legitimate business, by seeing if I was in the phone book -- so I just registered online, called them back, they saw it and granted me the certificate, then I unregistered.
Waste of time.
Anyway, your tool seem to get good image size on videos with lots of colors, but horrible size on simpler images. Using the --fast switch as it took 6 minutes to convert 387 frames to save 10% on filesize. I'm comparing it to ffmpeg with a pallete as it seems to get similar image quality with a smaller size in most cases.
Gist of my bat file. https://gist.github.com/Nodja/8ece6c3d866867877442e34bf67ece...
edit: After reading this after posting it, it looks as I'm super critical/aggressive. I'm just genuinely curious at what drove you to write the tool as there are already ways to achieve what you wanted. Didn't mean to antagonize you.
It is disgustingly easy to set it up, it is software none of us deserve.
I ended up with Comodo, which was "cheap". I then discovered that this was cheap for a reason: they did not provide the identity validation (something which was not clearly stated anywhere), and I had to pay for a notary certification (which was about twice as much as the certificate price), because apparently in the US an ID card is considered as reliable as your sport club membership card.
The whole Microsoft code certification is a shit show. It provides no security whatsoever, feeds an incredible number of incompetent parasites, and at the end is a real burden for open source developers like me, who want to get rid of the nasty Windows security messages, but also want to avoid being targeted by download sites bundling your binaries with some adware crap.
A "let's encrypt for code" ? Please sign-me up!
EV certs immediately gain trust: https://blogs.msdn.microsoft.com/ie/2012/08/14/microsoft-sma...
apparently sha2 signing wasn't working for him
https://news.ycombinator.com/item?id=17200491
>I would have signed with SHA-2, which for inexplicable reason is not default despite deprecation, but my signtool crashed when I enabled it.
We actually switched certificates (from StartCom to Globalsign) and the signing was wrong at first, so the message kept showing. When we fixed it, it went away immediately, even though certificate and author name changed...
Here's the article:https://blogs.msdn.microsoft.com/ie/2012/08/14/microsoft-sma...
"Programs signed by an EV code signing certificate can immediately establish reputation with SmartScreen reputation services even if no prior reputation exists for that file or publisher."
Code signing certificates are a great idea if you're a company who gets to charge me hundreds of dollars per year to say that I am who I say I am. Code signing doesn't seem so great from my perspective, because I don't want to have to pay hundreds of dollars per year to a cartel engaging in a protection racket. Unsigned code warnings are nothing more than them saying, "Gosh, it sure would be a shame if we scared away potential users (wink wink)." If the certificates were based on inspection of the actual source code and building the installer inside a trusted environment, that would be one thing, but that isn't how they get assigned. Certificates are assigned based on whether or not I want to give the trust cartel a lot of money. Fuck that.
An interesting solution could be that Windows users could get the ability to add additional root certificates for application sign keys to Windows installations.
However, precisely because those areas are so shady, it would help if there was a way to get code signing certificates of a lower pedigree but with pseudonymity. The shadier things get, the more likely there will be knockoffs with malware. The more likely there will be knockoffs with malware, the more likely some inexperienced user will accidentally get the (ill-signed) malware knockoff.
For your senior citizen browsing the web and clicking things, this dialog saves people. More often than you'd think.
Looking around schools is a pretty good way to see what average user might look like.
Also, users DO get the app from the publisher in this case. Windows provides SmartScreen, the developer provided the binary and signature (and was on his own as to how to get it)
The trickiest part was explaining to the 60-year-old bank teller why I needed all of these documents notarized and what they were for. I guess that's the one protection against forgery in this case -- notaries breaking the rules are dealt with pretty harshly where I live. They called me several times and her twice, but once that was done, I got an e-mail and everything was taken care of.
While I agree that requiring code signing certificates to run free software sucks, I'm curious where the thousands of dollars a year comes from? I finally broke down and purchased a code signing certificate[0] last year. The prices varied, but I don't recall seeing any for more than $300, and I was able to get my for $100 which is valid through Windows 10 and works on everything else that uses one of these EV certs. In addition to that, I purchased a Yubikey, which I wanted anyway (and having a desire to protect my code-signing key was the excuse I was looking for to purchase one of those), bringing the total cost for the first year to $140 (and subsequent years at $100). There is certainly a time cost, and it's really fun explaining that "no, I do not have a land-line phone" and "no, I don't get bills from my mobile phone company, but I can print out what qualifies as a bill from my Project Fi page[1]" all while trying to understand the accent of the non-native-English speaker I was working with.
[0] Not purely for signing open-source software, but I use it 99% of the time for signing Open Source software ... and miserable PowerShell scripts so that I don't have to remember to override the default security policy.
[1] The number of eye-rolls around the security theater involved in all of this was comical. They asked for photocopies of 6 or 7 different documents, all of which would have been trivial to forge with any information I wanted if I were so inclined. The only real verification around these documents is the notary requirement -- which, at least where I live, notaries are punished harshly if they don't follow the rules.
You can automate this with scsigntool.exe check out https://www.mgtek.com/smartcard
but yeah doing all this to publish signed exe under Windows is a PITA
That said, yes, this guy is doing it wrong. He should be using SHA-256, not SHA-1, and he should be using an EV cert (which takes more like 60 minutes to obtain than 6 months.)
Wrong. Windows is a closed source, proprietary platform. One would develop OSS for an OSS operating system.
(I say that as a full time Linux user, developer, and OSS advocate, btw).
Stallman himself would have no problem with that, if he's logically consistent.
They support C11 to the extent required by ANSI C++17.
For anything else, the offcial answer is to use clang or gcc.
In order to verify your company phone number, it has be shown in any of the links like : (www.dnb.com) or (www.hoovers.com) including local/national registration agencies and reputable third party databases.. So please update the Company name,address and Phone number in any one of the above web site.
My company is registered in Norway, and having the company's email and domain listed in the national company registry does not help. I'm currently in SE Asia, and I have to go back to to this:
[...] you can send an attestation letter signed by your attorney, Certified Public Accountant or Latin Notary (where legally recognized) verifying the telephone number. You can download sample text for the letter [...]
We need Let's Encrypt for code signing. But how can we automate identity validation? Verify the e-mail address or phone number with a national registry, where possible?
GlobalSign were able to help me, they were a bit more expensive but vastly better support than Comodo. Super friendly phone & email support. I did need to get a Yellow Pages listing for my business for them to verify me, but Yellow Pages offer a free online listing tier in Australia. You might be able to ask for a discount if their prices are a bit too high for you & you're switching from Comodo.
If you must have a Comodo cert, you could try buying through K Software (http://codesigning.ksoftware.net/). Mitchell Vincent is great to deal with, and I used his services for years. He could probably have helped me deal with Comodo verification, but I was just too exasperated by Comodo's support drones.
BTW, Chrome has a similar thing, compile an .exe, put it on a personal site, and try to download it.
Edit - hmm, it sounds like the dev got an EV cert though, because regular ones don’t require storing keys on a token. So I’m not sure what’s going on here...
https://www.globalsign.com/en/blog/microsoft-announces-updat...
Several days and a pile of cash fucking around with WIX and signtool for what exactly?
https://security.stackexchange.com/questions/109629/deprecat...
But yeah, it's a pain..
It's essentially a protection racket with price segmentation.
Every time I have to dabble in the world of Windows these days it really depresses me. Windows 10 is really a great OS underneath but every new update seems to add more layers of crap.
This is how painful it is to ship software for major platforms. Windows is by far the worst. Apple and Android are a bit better but not really great.
Turn on Developer Mode in "For Developer" Settings.
I maintain a desktop application (with MSI installer) for a niche industry with a few hundred users and for the first few weeks they had the scary red warning, but after then they started seeing the blue, non-scary pop-up, even for new binaries provided they're signed with the same certificate. We have a Comodo code-signing cert (non-EV though) which costs ~$70/yr through Tucows (remember them?).