I mean if they really wanted to they could blacklist your CN or O value in the certificate, or add you to the windows defender/smartscreen detection list, which will effectively kill your app for a good segment of the windows userbase.
I have code-signing certificates myself: the verification process did not fill me with confidence that the system is trustworthy - GlobalSign had me email them details of my DUNS/ UBI / business registration and a notarised copy of my driving license and checked that my name matched, and that was it. I could easily fraudulently obtain a code-signing certificate with a fake ID matching the name and state of some other vendor I just took a disliking to.
(I recognise that this system’s adding of barriers-to-entry does eliminate large numbers of opportunistic malware and provide a means to quickly disable installation and execution of revoked certificates - so I’m not calling for the system to be torn down!).
Having to pay money introduces a money-trail and a paper-trail. If a payment for a certificate is made with stolen CC details then the certificate gets revoked. This also effectively stops opportunistically-written malware taking advantage of current events (click bait email subject lines) to spread via email attachments.
The value from code-signing isn’t just the (I agree: very weak) attestation of the software’s author’s identity - but because it introduces a revocation mechanism and a reputation system - and creates barriers-to-entry that burden malware authors more than legitimate software vendors.
It’s not perfect, but don’t let perfect be the enemy of good.
Also remember that the only proven successful alternative to the current open PKI/CA system is the closed walled-garden approach favoured by Apple. I don’t think any Web-of-trust system has ever really been demonstrated as being feasible long-term without some WoT nodes evolving into pre-trusted/super-trusted nodes with the same power that CAs have today.
And at least with PKI+CAs you can add your own trusted root certificates and remove those you don’t trust.
Apple’s poor financial state under Sculley was more because they had an objectively poor product (going by the technical merits alone), a confusing product line-up, a failure to recapture the education sector that was quickly switching to Windows due to its enterprise-friendly features like Group Policy and compatibility with Directory Services like NetWare, and because it didn’t have a plan going forward into the 21st century.
I do note that in the 1990s under Sculley they both licensed macOS to third-party hardware vendors and were fine with PowerPC being adopted by other platforms (even Microsoft, and evening when it was incompatible with Apple’s architecture) - that’s the very opposite of the vendor lock-in-in that you’re describing. It can be argued that Apple’s “nice guy” approach further contributed to their decline - it certainly didn’t help raise sales nor their share-price.
Aldo consider when Steve Jobs returned they made deals with Microsoft to ensure Office would still be available for the Mac. Apple’s stewardship of WebKit was about driving open web-standards, even though Safari is very much Apple-exclusive. Apple also made a big-deal about how the then-new Mac OS X was a POSIX-compliant BSD system.
I think you’re confusing Apple’s aggressive control of the user-experience with IBM and Oracle-style lock-in. With IBM/Oracle a company or gov dept will have sunk $lots into a system that they cannot take away to a different vendor: there is literally no alternative than to continue with whatever gargantuan system their sales reps convinced the customer to buy. This is why banks and insurance companies are still rocking IBM Z-series today after 30+ years even though a system that’s just as resilient could be built for a fraction of the price on commodity hardware (I’m not going to pretend that Linux was a viable option back then, but systems like VMS or a project requirement to use POSIX were options back then). When people say that banks/insurance companies are “conservative” when it comes to technology I think it’s better to describe them as being technically inept or even corrupt which led to them being caught in vendor lock-in which paralysed them internally: I feel the arguments that they don’t want to risk losing billions over a bad technology move are just excuses for being unable to make a technology move even if they wanted to.
I believe that Apple sees that their controlling of the user-experience of its customers creates value for the user - whereas IBM/Oracle-style lock-in rarely does. I reckon 90%+ of non-developers using Apple hardware today (iPhone, iPad, Mac, etc) could switch to Android, Surface, and Windows PC respectively without losing much in the way of capability - but they would lose a cohesive and well-thought-out user-experience, which is Apple’s moat.
Nit: Safari shipped for Windows for a few years
They make a majority of the money in mobile.