Hacker News new | ask | show | jobs
by Eleison23 1401 days ago
The code-signing certificate says nothing about whether the program is worthy. The code-signing certificate authenticates the publisher. That's how it's supposed to be used. The due diligence for code security is up to the publisher, because they're staking their reputation by certifying it.

The certificate authorities are separately run, by the way. I don't know how you could say Microsoft has a protection racket when they accept certificates from disparate authorities.

Code-signing certificates enable users to discern reputation. A certificate confers a reputation and not holding a certificate means an unknown reputation.

If I drive a car without a license, I can probably drive that car for years as long as I'm obeying laws and not causing trouble. A police officer who pulls me over may perhaps not ask for a license after all, but he doesn't know my reputation of obeying traffic laws; he's got to check my privilege. A driver's license in my jurisdiction carries reputation beyond just the driving privilege: infractions will rack up points.