Hacker News new | ask | show | jobs
by Someone1234 73 days ago
Because a bad guy can also generate their own signing key and deploy it alongside the installer.

See Notepad++ for how that winds up.

1 comments

Then you can publish the public Code Signing certificate for download/import or publish it through WinGet.

Using Azure Trusted Signing or any other certificate vendor does not guarantee that a binary is 100% trustworthy, it just means someone put their name on it.