sigstore will be a non profit / free to use service. Think Let's Encrypt for software signing.
My hope is that we shift the paradigm so that consuming untrusted software via packages / dependencies etc becomes as unappealing as serving a website over just plain ole HTTP has now become.
In order to make that shift, open source communities require a free and easy to use service and this is what we hope sigstore will become, which is why it's a Linux Foundation project with all code being developed and maintained by a community.
It's becoming increasingly difficult for me to run my own code, that I am perfectly happy to sign myself, on my own devices. That might seem like a fringe case. But it shows a deeper problem:
I do not trust you. I don't even know you in the first place.
Yet you (well, as part of a goup) are asking me to give you more power over my devices.
What is this push towards centralizing trust ?
Example: Firefox extensions need to be signed now. I can't send my friends the extensions I wrote myself. There is just no way. I can't go over to their house, sit next to them, and install my self signed-root certificate, and have their version of firefox trust it.
It must be signed by Mozilla: An organization that most people will never ever in their lives's interact with. That makes no sense.
And not even to speak of trying to install private Root CAs into iPhones or Android devices.
How does your solution empower users to own their own devices, and not have them owned by someone they are separated from by several degrees and whom they have never met ?
https://certificate.transparency.dev/
and less like AuthentiCode or app store code signing.
It doesn't say this on the announcement, but looking at the actual PKI service (https://github.com/sigstore/fulcio), it seems to be entirely possible to self-host the service and roll your own CA.
And further to this, anyone could stand up their own sigstore service. In fact we expect some of the bigger oss projects to do just that.
You can install your company’s internal CA certs as part of any MDM package.
And products like HashiCorp’s Vault let you manage the whole CA and signing certs etc
I think that compromised dependency chains are a nightmare, and we're just getting started.
I write Apple apps, and dread the whole provisioning thing (which they seem to change, regularly), so this is not heavy-duty at all.