TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Notepad++ drops code signing for its releases

496 pointsby pmhabout 6 years ago

34 comments

Svokaabout 6 years ago
Windows signing is a ripoff, $500&#x2F;year you&#x27;re getting nothing. Your certificate is not trusted. You have to &quot;get reputation for it&quot; before Windows Defender would stop giving users warnings. Also, renewing certificate is not a thing. Every time you have to get a new one, with same story of &quot;reputation&quot; again.<p>[1] <a href="https:&#x2F;&#x2F;www.digicert.com&#x2F;order&#x2F;order-1.php" rel="nofollow">https:&#x2F;&#x2F;www.digicert.com&#x2F;order&#x2F;order-1.php</a>
评论 #19330350 未加载
评论 #19330114 未加载
评论 #19331240 未加载
评论 #19330604 未加载
评论 #19332114 未加载
评论 #19330190 未加载
评论 #19331741 未加载
burtonatorabout 6 years ago
I created a huge rant on code signing certificates here:<p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=mwuk0E-tfeg" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=mwuk0E-tfeg</a><p>It&#x27;s a nightmare. Complete scam.<p>I needed this for Polar: <a href="https:&#x2F;&#x2F;getpolarized.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;getpolarized.io&#x2F;</a><p>Mind you... it&#x27;s Open Source but I still want my users to be able to download it without warnings.<p>No joke - it took me 2 weeks to get the CSC with about 4 hours per day working on just this CSC issue.<p>It&#x27;s just a labyrinth of insanity from not having a listing on D&amp;B to them insisting I pay $2k to expedite it.<p>I still don&#x27;t have one from Apple because it requires a D&amp;B number so I had to get a personal cert from them.<p>I went with a cheap one for Windows BUT it gives errors on install for like the first 1k downloads until Windows says it&#x27;s legit.<p>It&#x27;s a complete scam.<p>BTW.. if you get in the MS App Store you don&#x27;t have to worry about a CSC so that&#x27;s good I guess.
评论 #19331223 未加载
评论 #19332214 未加载
评论 #19330922 未加载
fjabreabout 6 years ago
I remember the good old days when people were actually trusted to do their own research before downloading a potentially dangerous exe.<p>Now all we have are app store and certificate rackets. Im looking at Google and Apple too. Shame on the industry for accepting 30% revenue share on their services. The idea of an app store is great but not when it excludes other legitimate ways of installing software on device.<p>These practices are anticompetitive and monopolistic.<p>Good for Notepad++. I couldnt agree more with its sentiment.
评论 #19329768 未加载
评论 #19330009 未加载
评论 #19329806 未加载
评论 #19329850 未加载
评论 #19330243 未加载
评论 #19329813 未加载
评论 #19330030 未加载
评论 #19329866 未加载
评论 #19329880 未加载
评论 #19330613 未加载
评论 #19332198 未加载
评论 #19330052 未加载
评论 #19332893 未加载
评论 #19330512 未加载
评论 #19330202 未加载
评论 #19330075 未加载
Wowfunhappyabout 6 years ago
What <i>really</i> pisses me off is code signing for drivers. To install an unsigned driver in 64-bit Windows 10, you need to reboot your computer into a special menu that can only be navigated with a USB keyboard (which I have to lug out of the closet, since I normally use Bluetooth). That in itself wouldn&#x27;t be so bad, except the setting persists <i>only until the next reboot!</i> †<p>This is all in stark contrast to macOS&#x27;s System Integrity Protection, which I can turn off once to never be bothered again.<p>I understand why Microsoft would enforce higher standards on drivers which can touch the kernel. But, the same fundamental problem applies: it isn&#x27;t reasonable for non-profit, open source developers—many of whom <i>I</i> consider perfectly trustworthy—to pay hundreds of dollars for a certificate! Let me make the final decision about who I trust. It&#x27;s my machine—I even built it myself!<p>The primary place I run into this problem is with drivers to support weird video game controllers.<p>---<p>† You can enable a &quot;testsigning&quot; mode via the command line which persists across reboots, but this only seems to work for certain drivers. If anyone can explain why it <i>sometimes</i> works, I&#x27;d appreciate it, as my research has never turned up anything.
billforsternzabout 6 years ago
I&#x27;ve been slowly improving my open source Windows chess program Tarrasch <a href="http:&#x2F;&#x2F;triplehappy.com" rel="nofollow">http:&#x2F;&#x2F;triplehappy.com</a> for nearly 10 years. One of my improvement plans has been to put on my big boy pants, and spend the money and time needed to sign the program. I thought it was a big part of the program graduating and becoming a serious software citizen. After reading the comments here I am reconsidering and might save myself the pain. Thanks Hacker News!
fbelzileabout 6 years ago
I&#x27;m going through a &quot;renewal&quot; right now... The archaic maze of validation is also getting on my nerves. It&#x27;s been three weeks now that I&#x27;m waiting for a phone call to validate my phone number. This article is making it so tempting to cancel my order.<p>The plethora of support emails is what motivated me to get one in the first place. I used to get accused of giving users a &quot;virus&quot; and getting into infinite loops on why they should trust me. I&#x27;m sure I was wasting more than $100&#x2F;year of my time responding to these emails, so I just gave in and got one.<p>Now, I don&#x27;t know what to do.
评论 #19331708 未加载
tabulatouchabout 6 years ago
Where do I sign for a petition to have a free CA like LetsEncrypt for Code Signing?
评论 #19330188 未加载
评论 #19330423 未加载
评论 #19330231 未加载
评论 #19330223 未加载
评论 #19330169 未加载
gruezabout 6 years ago
Why not use something like certum[1]? It&#x27;s $69&#x2F;year (cheaper if you already have a smartcard), but the CN ends up with something like &quot;Open source developer, [full name]&quot;. It&#x27;s not &quot;notepad++&quot; like the author wants, but it&#x27;s still better than nothing.<p>[1] <a href="https:&#x2F;&#x2F;en.sklep.certum.pl&#x2F;data-safety&#x2F;code-signing-certificates&#x2F;open-source-code-signing-984.html" rel="nofollow">https:&#x2F;&#x2F;en.sklep.certum.pl&#x2F;data-safety&#x2F;code-signing-certific...</a><p>edit: updated price
评论 #19329625 未加载
评论 #19329617 未加载
评论 #19329637 未加载
评论 #19329651 未加载
评论 #19333884 未加载
评论 #19330189 未加载
评论 #19330671 未加载
foobarbazetcabout 6 years ago
In case anyone reads this far down:<p><a href="https:&#x2F;&#x2F;docs.microsoft.com&#x2F;en-us&#x2F;windows-hardware&#x2F;drivers&#x2F;dashboard&#x2F;get-a-code-signing-certificate" rel="nofollow">https:&#x2F;&#x2F;docs.microsoft.com&#x2F;en-us&#x2F;windows-hardware&#x2F;drivers&#x2F;da...</a><p>Follow the steps under “Buy a DigiCert EV code signing certificate“.<p>You’re welcome. ;)
评论 #19400213 未加载
asveikauabout 6 years ago
Interesting that they will check the hashes of dependencies at runtime. But then I start to wonder - why dynamic linking if the library can&#x27;t be replaced?
评论 #19329922 未加载
评论 #19329686 未加载
vkakuabout 6 years ago
Good for them! Certificates are a bad business today. The only reason I&#x27;d get one is because things like letsencrypt exist;<p>Orthogonally, I also think that $99 App Store fees are a terrible waste of money. You should get charged only when submitting to an app store for review.<p>There are plenty of root certificates that came installed on my computer, and I don&#x27;t even trust them. Why would these CAs charge so much for so little value?
评论 #19331961 未加载
xpaulbettsxabout 6 years ago
At the end of the day, Notepad++ can&#x27;t get a &quot;Notepad++&quot; cert because &quot;Notepad++&quot; is not a Legal Entity (i.e. a corporation or living person). At least from a policy perspective, Microsoft will only consider Legal Entities to be valid code signatories.<p>Yes, this <i>is</i> stupid and outdated, I agree - I personally think that Keybase issuing code signing certificates and being able to verify that the person who signed this also owns this GitHub and that Twitter account would still be super valuable.
herfabout 6 years ago
Could post to Microsoft Store, which would let them do this for free.
评论 #19330055 未加载
评论 #19330264 未加载
mc32about 6 years ago
Microsoft should jump in and afford the developer the cert out of good will given MS until recently never had a good alternative to NP++.
评论 #19329819 未加载
aruncabout 6 years ago
These kind of code-signing certificates should be free for free and open source projects.<p>D Language community recently [1][2] bought a certificate reluctantly to satisfy Windows defender, virus scan warning, etc. Sadly we are stuck with this immoral blackmails.<p>[1] <a href="https:&#x2F;&#x2F;forum.dlang.org&#x2F;post&#x2F;sclqnbggytmyetwrxppb@forum.dlang.org" rel="nofollow">https:&#x2F;&#x2F;forum.dlang.org&#x2F;post&#x2F;sclqnbggytmyetwrxppb@forum.dlan...</a><p>[2]<a href="https:&#x2F;&#x2F;dlang.org&#x2F;changelog&#x2F;2.082.0.html#signed_windows_binaries" rel="nofollow">https:&#x2F;&#x2F;dlang.org&#x2F;changelog&#x2F;2.082.0.html#signed_windows_bina...</a>
pierotofyabout 6 years ago
Beside the fact that code signing is a racket, <a href="https:&#x2F;&#x2F;codesigncert.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;codesigncert.com&#x2F;</a> gets you a Comodo cert for $75.
newnewpdroabout 6 years ago
This is slightly off-topic, but do indie game developers publishing on Steam have to jump through this hoop to support Windows? Are all Windows games on Steam signed?
royceabout 6 years ago
I&#x27;m startled that there&#x27;s no mention of app whitelisting yet.<p>Code signing reduces ops overhead and latency in environments that are using app whitelisting.<p>If the code is signed, then the signing certificate can be trusted <i>once</i>. All upgrades and patches that are signed with that certificate can be <i>automatically</i> whitelisted, with no intervention from teams managing the whitelisting.<p>But if the code <i>isn&#x27;t</i> signed, then if even a single byte changes in the executable, it must be re-whitelisted - usually manually.<p>The more signed apps there are, the easier it is for companies to start using application whitelisting, the fewer people are needed to maintain it, and the faster patches to those applications can be deployed. Making it easier for companies to move to whitelisting increases security for the ecosystem in the aggregate.
JordanBoulanabout 6 years ago
Anyone have any source that cites it&#x27;s sources for the profit margins on code signing rackets. I imagine for mobile the margins are especially high since phone o&#x2F;s design makes it much easier to put less effort into audits. I bet the profits margins in both mobile and standard are absolutely monsterous. By the principals of business I assume they put in the least amount of effort possible while still putting in enough to protect themselves from blame
jimktrains2about 6 years ago
&gt; I realize that code signing certificate is just an overpriced masturbating toy of FOSS authors.<p>I&#x27;m not sure what the author means by this.
评论 #19329700 未加载
评论 #19329684 未加载
评论 #19330560 未加载
评论 #19331869 未加载
crispyambulanceabout 6 years ago
Does this mean that some users won&#x27;t be allowed to install Notepad++ because it&#x27;s not signed? I know some corporate environments have restrictions on downloaded installers.<p>Off topic, but I have to say that whenever I need to open <i>hundreds</i> of files at once and perform regex operations-- this editor rocks that task like no other. Kudos to Notepad++
评论 #19334136 未加载
joelennonabout 6 years ago
You can buy a Windows code signing certificate from DigiCert for $74&#x2F;yr (EV certs are $104&#x2F;yr) by going through this link - <a href="https:&#x2F;&#x2F;www.digicert.com&#x2F;friends&#x2F;sysdev&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.digicert.com&#x2F;friends&#x2F;sysdev&#x2F;</a> - much easier to swallow than the standard $499!
forgery--about 6 years ago
Companies using Carbon Black Protection (Bit9) or similar application whitelisting systems use signing certificates to help approve software. Once I approve the &quot;Simon Tatham&quot; certificate for my company, anyone can download the latest version of PuTTY and run it without issue. I wish the trend was for more software to be signed.
wozerabout 6 years ago
In Germany, Notepad++ is ubiquitous on Windows computers (every developer has it). Is it like this in the US, too?
评论 #19330945 未加载
评论 #19330501 未加载
评论 #19330474 未加载
评论 #19330660 未加载
评论 #19330509 未加载
runarbabout 6 years ago
I am in a similar situation myself with Portable-VirtualBox. Does anyone know where one can get a reasonably priced code signing certificate?<p>Preferably one that does not require a USB dongle. Did order one from Comodo, but was not able to get the USB dongle to work.
laytheaabout 6 years ago
I can&#x27;t be alone in not caring too much about the cert.<p>Notepad++ - Crack on!
keithnzabout 6 years ago
other than Microsofts signed software, the fact it is signed doesn&#x27;t really mean much to me as I have no idea what anything should be signed with. What I tend to trust is that I know specifically where I went to get a piece of software. It is easier for me to tell what an official site is rather than an official signature
agumonkeyabout 6 years ago
Let&#x27;s see if that affects usage or not. I&#x27;m sure people like it so much they won&#x27;t care.
duxupabout 6 years ago
&gt; I realize that code signing certificate is just an overpriced masturbating toy of FOSS authors<p>What does that mean?
docodeabout 6 years ago
I&#x27;m on the same track. Definitely we need Let&#x27;s Encrypt for code signing certificates!
blibbleabout 6 years ago
register Notepad++ Limited for about £10&#x2F;$15?
评论 #19329790 未加载
评论 #19329811 未加载
everyoneabout 6 years ago
Good on &#x27;im!
draw_downabout 6 years ago
Feels like there&#x27;s an opportunity for some kind organization to help open-source developers out with this. It shouldn&#x27;t be this hard for someone trying to give away good work to the world. I used Notepad++ for a long time, and still might if I spent any time in Windows.
评论 #19329713 未加载
kpcyrdabout 6 years ago
It seems the author is very focused on signing with x509.<p>I&#x27;m wondering if they are aware of free alternatives like signify or pgp that would work just as well (minus the windows UAC thing). Right now there are only checksums but no way to verify they are from the author and are distributed on the same server as the binary, so the only security layer is https.
评论 #19329708 未加载
评论 #19329798 未加载
评论 #19329766 未加载
评论 #19330410 未加载
评论 #19330492 未加载