• korstmos
    link
    fedilink
    16111 months ago

    Because paying a few grand a year for a certificate somehow makes your software more trustworthy

      • xigoi
        link
        fedilink
        2711 months ago

        They also weed out a lot of legitimate software, especially if it’s non-commercial.

          • @WhyIDie
            link
            3
            edit-2
            10 months ago

            deleted by creator

    • @[email protected]
      link
      fedilink
      2111 months ago

      Well it at least is an obstacle. Broke hackers won’t get it or will have to work harder to get around it.

      • @[email protected]
        link
        fedilink
        4211 months ago

        That’s the intention. In reality lots of genuine devs can’t afford it, so people get accustomed to just ignore the whole thing.

    • @[email protected]
      link
      fedilink
      1011 months ago

      Even more lols when you are gigabyte and your private key leaks. Also when you are gigabyte and your signed driver is used to privilege escalate malware.

    • @[email protected]
      link
      fedilink
      English
      411 months ago

      And that’s why certificates can be revoked, that’s the whole point, trust. It only costs a few hundred a year per Microsoft’s documentation and approved vendors so it doesn’t seem that much of an ask. At the very least you can look up the developer yourself, harder to do if the package has no identity associated with it

    • @Tathas
      link
      211 months ago

      Gigabyte has entered the chat.