zlacker

[parent] [thread] 10 comments
1. adzm+(OP)[view] [source] 2026-02-02 03:04:14
Code signing certs are unfortunately expensive
replies(3): >>firest+S1 >>1una+ap >>Chaosv+Z3b
2. firest+S1[view] [source] 2026-02-02 03:20:21
>>adzm+(OP)
$700+ at Sectigo for two years

Something of Notepad++ size might think about it now

replies(2): >>abeyer+Wa >>hjoutf+go
◧◩
3. abeyer+Wa[view] [source] [discussion] 2026-02-02 05:02:40
>>firest+S1
"of Notepad++ size" is basically one guy in his free time, no?
replies(1): >>eviks+Xd
◧◩◪
4. eviks+Xd[view] [source] [discussion] 2026-02-02 05:37:14
>>abeyer+Wa
"But look at those downloads, they magically print money"
replies(1): >>firest+On
◧◩◪◨
5. firest+On[view] [source] [discussion] 2026-02-02 07:31:39
>>eviks+Xd
Notepad++ is Windows-based and could use the Windows store instead of the built in updater. Microsoft charges a one time fee. It would pass SmartScreen checks. His website has a bunch of ads integrated which I assume are there to help pay for hosting.

Mr. Ho already has hosting charges and he uses GitHub. For those who use GitHub, he could continue his GnuPG method for signing. Additionally, GitHub integrates with Sigstore. Windows wouldn’t trust his signature but at least there would be better traceability. Version 8.8.7 labeled “authenticity guaranteed” is a step in that direction.

The real “issue” here was his outside hosting platform for updates from my reading of the article.

◧◩
6. hjoutf+go[view] [source] [discussion] 2026-02-02 07:36:22
>>firest+S1
the issue was not the money, but that it was difficult to get a certificate without having some sort of legal entity
replies(3): >>firest+rp >>anonno+ty3 >>Chaosv+m4b
7. 1una+ap[view] [source] 2026-02-02 07:46:43
>>adzm+(OP)
$0 at SignPath. Quite a few OSS projects use it.
◧◩◪
8. firest+rp[view] [source] [discussion] 2026-02-02 07:51:04
>>hjoutf+go
Certum.eu has this figured out.

https://support.certum.eu/en/code-signing-required-documents...

https://shop.certum.eu/open-source-code-signing-on-simplysig...

$49 (EU) Gross

◧◩◪
9. anonno+ty3[view] [source] [discussion] 2026-02-03 02:24:39
>>hjoutf+go
Delaware LLCs are "cheap," but you're still looking at $300-500 a year in fees.
10. Chaosv+Z3b[view] [source] 2026-02-05 01:32:53
>>adzm+(OP)
You don't even need a certificate to prevent update tampering like this. The updates could have shipped with an ECDSA signature and this wouldn't have happened. It's also free and doable in an afternoon.
◧◩◪
11. Chaosv+m4b[view] [source] [discussion] 2026-02-05 01:35:48
>>hjoutf+go
It was negligence. You don't need a certificate to prevent update tampering.
[go to top]