Hacker News new | ask | show | jobs
by anaisbetts 37 days ago
I don't think this is true. A normal CS signing cert is sufficient for most commercial apps - you will get the SmartScreen warning for a few days but it will go away fairly quickly.

The important part is that SmartScreen reputation is URL-based, you need to make your initial download URL consistent. If you are constantly rewriting it (i.e. with a version #) it will break. It's ok if the original URL hits a 302 to the latest version.