Microsoft hurts sales of indie developers with “not commonly downloaded” error
twitter.com
twitter.com
As a user you have to click several screens away in order to install my software. Software which is properly signed with a certificate, but well it isn't popular enough according to Microsoft to be trusted.
Not sure since when "popular" equated to "trusted".
You can click on some links to report this to Microsoft and they promise to look into it according to their automated report.
Of course.. now several months later nothing has changed.
Even if they would whitelist a single download... the next update would have the same problem again.
It is easier to release the macOS version nowadays then the Windows version and that's not really an accomplishment.
Otherwise people would buy without installing... or never upgrade to the latest version (I try to release regularly) and the "not commonly downloaded" error is still there.
It would probably be cheaper to try and get an EV code signing certificate (if I can even get one as an indie dev)
But not like it matters; you already have to randomly enter your password in random prompts that look like phishing attempts and blindly accept security warnings to do the most normal of things.
- Malware can be signed - Popularity != trustworthiness - Software "trustworthiness" shouldn't be depended on. Strong sandboxing avoids malware
Frequently updated software, while being more secure, will be more affected by this issue.
Therefore, this approach by Microsoft is making everyone using popular but often updated software, less safe by design.
Now we'll have to deal with every game release giving big instructions on how to circumvent this message. Great.
First it warns you to not save the download.
Next up you get the warning from the screenshot
Then you get the normal UAC prompt that shows your company details.
After that the installer itself comes up.
I think I even am forgetting a click.
It is a pretty unpleasant install experience. Another developer told me that you might be able to cure this by buying an EV certificate instead.
Yet another one said that the company he works for (pretty well known) has the same issue.
Of course I already bought a normal multi-year certificate which wasn't cheap. So now I would have to throw that away and buy an EV certificate? Which are even more expensive and don't really offer more security beyond the "it's more expensive" limit.