Putting the price aside just for a second, are there really people out there who think that code signing isn't worthwhile? Remember paint.net/filezilla having ad links to "Download Now" that would download... not paint.net or filezilla?
Putting the price aside just for a second, are there really people out there who think that code signing isn't worthwhile? Remember paint.net/filezilla having ad links to "Download Now" that would download... not paint.net or filezilla?
Still, if a major problem is ads directing to malware-infested downloads, how about before we start requiring OSS projects to become legal entities, we apply the same idea to advertisers? Why not introduce "ad signing", or better yet, some regulatory scheme, where you cannot provide an ad, and you cannot display an ad, unless you're a recognized legal entity with a certificate chain to back it? That would address a part of this problem at the very source (and address so, so, so many other problems too).
But I get it. We have to disempower the innovators and make it hard for honest people, because the whole computing industry makes almost all its money from scoundrels fucking the society over, and while we can't admit to it out loud, we can talk up the threat of overt bad actors, so that no one pays attention to more covert bad actors running the show.
If a user has the presence to know whether or not they should expect a specific Open Source program to be signed, then they probably can get it directly from the website? And if they can't find an official download link, then they probably won't realize anything is wrong when they get an unsigned application because how on earth would someone know whether or not Paint.net is signed without visiting the official website to check? So either the malicious ads get caught and they aren't displayed, or... I mean, I don't know, unless there's something I'm missing I just don't see how a malicious ad that directs someone to a fake download page for Paint.net isn't going to be able to get crap on a victim's computer regardless of what Paint.net separately does to the real binaries.
The user doesn't download the real binaries, that's the entire scam. The user doesn't know if Paint.net signs its binaries and they don't know if the warning they're getting from the OS should or shouldn't be ignored. So on top of shifting the burden onto the wrong people, it's also not 100% clear to me that shifting the burden onto developers actually improves security all that much?
I'm not against application signing, it can be an important part of security, but not when it's a manual process that costs $600. And not just on its own in isolation, and not when it's an optional process that (because of the cost) many applications aren't going to participate in to begin with. I'm not against signing applications on a conceptual level; I like being able to verify releases. But the Windows/Mac signing process sounds a lot like security theater to me.
It doesn't give you any guarantees about the binary being free of malware - only that it's really published by the entity you got it from.
Granted: Now an actor who wants to inject malware has to hijack the build process rather than only the website, but somehow I'm not convinced that's worth 600$/year and a lot of technical effort that could be put into securing the distribution chain.
If you can’t put $600/year into signing your binary, I don’t know how much effort you’re going to put into securing a distribution chain.
Oh, you're not? Then why should the volunteer developers do so?
And what’s the issue with the reason behind it? The CA/B Forum made this decision after a lot of deliberation. What’s a better partial solution to this problem given the state of the world today?
They're widely known for shipping malware with at least some of their downloads (windows only maybe?), and completely ignoring posts on their forum about it.