Why does my installer get flagged by Windows?
blog.pakkly.com
blog.pakkly.com
But unfortunately that's just a rant. I don't know if there even if a better solution. The money barrier (rather than verification) will stop some opportunistic malware, but big players won't care.
As far as I can tell, the video is the only public information on the non-GA service: https://youtu.be/Wi-4WdpKm5E?t=529
I’m ready for bipartisan gutting of big tech.
After having gone through it, I agree with other posts that the main annoyance is the verification process and weeks of delays/back-and-forth. That, and the inconvenience of now having a single point of failure in the build process (unless multiple certs are purchased).
Except that's not quite true is it.
Most (all ?) devices (even the cheap USB ones) have secure wrapped backup/restore mechanisms.
All you had to do was set up your device correctly in the first place (since the wrapping can't be activated retrospectively).
Some of the cert vendors even have ready-made instructions available to follow on their website telling you exactly how to do this: https://www.ssltrust.co.uk/help/setup-guides/mofn-setup-nitr...
RTFM as they say. ;-)
I don't follow.
The purpose of storing keys in hardware is to irreversibly protect the key.
If you then wish to be silly and hardcode the PIN to the hardware in your release scripts, then that is your prerogative.
If its the cost of an HSM you're alluding to, even that is a non-issue with a Yubikey or Nitrokey.
It somehow detects if you're in an RDP session, and shows that there are no hardware tokens attached if that's the case. No message or warning whatsoever. My only Windows PC is headless and I lost several hours trying to debug this.
The entire EV cert process is such an outrage. My cert vendor advertised that the validation process would take 2-3 business days if all docs were in order, DUNS info correct, etc. I spent a lot of time ahead of the order ensuring the docs were indeed in order, and the process still inexplicably took 9 business days.
If TeamViewer acts on an already logged-in local session, it should work well.
We had a Digicert code signing certificate that used a hardware key connected to the Windows VM. Unfortunately it required a password to be manually entered each time the code was signed.
To automate this, I wrote a little AutoHotkey script that watched for the password dialog and entered the password.
There wasn't any RDP issue because we didn't use RDP, just a Windows VM that didn't need any user intervention. (It could have been a separate physical machine, but since we had the Mini anyway and it had the capacity, it was convenient to have it do both the Mac builds and the Windows code signing.)
I sometimes think there are few problems that AutoHotkey cannot solve.
And stolen certificates make the whole code-signing house of cards falls apart - you can't trust something signed by Realtek if it was not, in fact, signed by Realtek!
Of course, hardware tokens aren't a panacea: Some malware authors simply set up a shell company and get a certificate issued to that company.
[1] https://www.trendmicro.com/en_us/research/18/d/understanding...
I think there was a good episode about that in the Risky Business podcast.
Do whatever you want with that information.
Do whatever you want with that information.
FTA btw "Essentially you have the option of two different kinds of certificates and three different price levels, depending on your urgency and user sensitivity."
Maybe you need to change something about your application.
"Essentially you have the option of two different kinds of certificates and three different price levels, depending on your urgency and user sensitivity."
Over the period of several years this happened to me on at least half a dozen occasions and recently in a two week period it happened three times.
Fortunately, in my experience this has always been fairly easy to fix, as it just requires submitting a false threat report to Microsoft Defender:
https://www.microsoft.com/en-us/wdsi/filesubmission
Each time this happens I just copy my stock standard false report into the fields of that link and within 24 hours Windows Defender is updated.
Anyways, there is no general heuristic to distinguish a good actor trying to prove their legitimacy from a bad actor trying to fake legitimacy. This is the essence of parasitism.
https://devblogs.microsoft.com/oldnewthing/20110310-00/?p=11...
walls and ladders - ill remember that.
https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31...
He doesn't quite come out and say what "being on the other side of this airtight hatchway" means - it appears only in the title. But the post makes it clear what it alludes to: if you're already in a position to execute arbitrary code on the target machine in the security context you want, then you don't need to jump through further hoops, because you're already there.
It's covered in the article: buy an EV code signing certificate.
Without a cert etc most people shouldn't be installing the applicarion at all. Thats the simple advice for most people, especially if some other trust is already in place, eg from someone you actually trust.
Also, this remains a constructed industry with only marginal benefits and major issues. Anyway...
I've never had a smooth ride getting a Code Signing Cert, always some stupid bureaucratic rubbish to deal with, or the need to run some stupid obsolete browser in order to actually get the thing, and I know at least 2 others who also ran into the same crap.
Malware writers use this trick to bypass SmartScreen. Chrome's equivalent protection also whitelists GitHub/...
[1] https://github.com/rcmaehl/WhyNotWin11 (used for test as I thought I remembered seeing this with a build from earlier this week)
I'm not sure what to do anymore. We are a small company with few customers. Slowly gaining reputation over time does not seem like a viable path.
We have problems with smart screen.
Can you recommend a certificate provider?
A few years ago I had to go through the process of getting a certificate for signing Windows application. I provide some details here: https://henvic.dev/posts/cs-security/