We (sqlitebrowser.org) have recently started using them for signing our Windows builds.
Ironically I've seen tons of actual malware that doesn't even give the slightest warning.
This is definitely the case and has been my experience, as well.
We live in some dark times when it comes to building and sharing anything as small developers, especially if the things you're building are free.
I stopped updating my open-source Mac apps because I can't justify the cost of jumping over artificial hurdles Apple puts in place that ensure users can't run the apps they want to use. I have other hobbies where spending money actually gives me tangible goods and benefits versus paying an arbitrary yearly tax for the privilege to build stuff that ultimately benefits Apple.
Which is deeply ironic, if you think about it.
This world is just awesome. :)
hah, that's the exact reason I stopped using os x and went full Linux on my old Mac book air about 8 years ago.
The alternative is not signing your binaries and explaining to users that they can run them by right clicking and selecting "Open" from the menu.
> The alternative is not signing your binaries and explaining to users that they can run them by right clicking and selecting "Open" from the menu.
That's what I'm doing now, and it's still an issue, unfortunately. Non-power users are not going to remember the right-click -> Open ritual when they just double-click on everything else.
And the warnings Gatekeeper shows also caused users to think their apps, and even computers, were broken or hacked.
Anyone can just get their malware signed by just throwing some dollars at it.