Software Certificates - Code Signing

Scan125

Member
Joined
Apr 30, 2014
Messages
664
Reaction score
239
Location
UK
Thought I would raise this hairy thorn as the whole world of both software and web site certificates is changing.

Suggest a read of https://www.grc.com/sn/sn-1059-notes.pdf

I think we have all had issues with AV programs, Windows Defender, others, throwing wobblies at a lot of software, especially small niche software as time progresses.

Typical issues are:

o No formal code certificate or even a "self signed" cert being frowned upon
o Cloud base ratings - e.g. if it used by millions it is deemed ok
o False positives by various engines affecting so AV programs and not others

Now I'm the author of Scan125, Scan75 and other programs which are free/charity ware based. There is NO WAY I can afford expensive certificates.

So I checked, out of interest ProScan and ARC software downloads and they do not have certificates either. This is not a criticism of them or any other, lets say' exclusive / niche software.

Me / these authors do our programming for a number of reasons but generally speaking we love what we do, we want to help radio users, a modest income/donations supports the costs we already incur with hosting etc.

To me it seems the way all this security, restrictions, cert income generation, stitch up by those agencies/authorities is ultimately going to kill off our hobbies with regards to independent software from real users.

Even if you make your PC accept non certificated there are still those hoops and loops that many users don't really understand resulting in "required support" from the authors.

Would not surprise me if that in the future any website hosting un-certificated software will be banned/block thus not allowing the software to be download.

For me as my software generates money for charity I suspect I would have to find a cert authority that would be willing to grant me a free license. As it happens I already have a free licenses for some software/components I use in my software development thanks to the generosity of their authors.

However I just can't see any cert authority doing similar.
 

pb_lonny

VK7AAL - Launceston Radio Scanning Blog
Joined
Jul 2, 2012
Messages
2,308
Reaction score
830
Location
Tasmania
Sadly this is becoming more of an issue. Due to this, I now just code for my own usage.
 

Scan125

Member
Joined
Apr 30, 2014
Messages
664
Reaction score
239
Location
UK
Sadly this is becoming more of an issue. Due to this, I now just code for my own usage.
Well there have been times that I have had to help users where AV programs, windows, ... baulks at my software and one then gets sort of entwined and dragged into the specifics relating to their PC. With all the different AV programs out there, some complaining and some not it gets rather complicated and tedious. The AV program vendors don't make it easy to report false positives especially if you don't have their software on your system. Also some require you to create and account to report stuff.

Will all this hassle no doubt I will eventually have to give up and just code for myself OR start charging. Charging has it's issues as well as the income creates tax issues which I don't want to get involved with again with regards to annual tax returns, accounting etc.
 

pb_lonny

VK7AAL - Launceston Radio Scanning Blog
Joined
Jul 2, 2012
Messages
2,308
Reaction score
830
Location
Tasmania
Windows defender was the worst for me. In the end, I gave up compiling an EXE file and just run my database via my IDE now.

I see a time when hobby coding is not a thing and unless you pay for a code signing certificate, you won't be able to share your program with anyone else :(
 
Top