This requires identity validation and controls for it to actually work, which is fundamentally incompatible with a Let's Encrypt-style pretend-CA.
This means storage of keys in hardware. Otherwise code signing keys are stolen and used for malware distribution in high profile attacks. This happened one too many times hence the more stringent requirements.
Ironically these guys want their cake and eat it too, there is no reason they couldn't just manually sign release builds which come once in a while. Many small OSS projects do this. No, they want full automation with an organization cert and now are complaining about meeting the requirements for that.
I wish we had a cryptographic verification mechanism based on code and reproducibility of their builds, and local-sensitive hashing mechanisms rather than the current ones.
Technically this might actually be a decentralized ledging use case that makes sense.
And meanwhile, in Linux land, people will install things by piping curl into bash[0][1], so the bar is just not that high. And the ultimate answer to security will come from better app sandboxing, not from charging every native-app developer in the world $700/year for a code signing certificate.
[0] https://docs.chef.io/chef_install_script/ [1] https://github.com/zyedidia/micro#quick-install-script
Just because some operating systems are decades behind on security that does not mean that security does not matter.
With a self-signed certificate, you are effectively your own PKI. The goal is generally to deduplicate that kind of work while also providing better security properties than “my host trusts self-signed certificates from a root CA that I keep on disk somewhere.”
I get the feeling that it's exactly what Windows "intends to imply or guarantee", it's just taking a long time to get there. The whole code signing part is trying to create a reality where to be able to create software for Windows, you need to be a business entity, and need to have business relationships with Microsoft - directly, or transitively. Basically, a corporate web of trust.
Is this an inside joke in the community or maybe even a an official take?
Also consider that another widely-used scheme implementation is called Guile.