Hacker News new | ask | show | jobs
by lazov 16 days ago
The commit history is a mirror of the real codebase, I wanted to show people that I've been working on this for a long time and that it's not vibe coded ai slop. In retrospect it seems that it was a mistake to do this.

Neverclick is digitally signed with Microsoft Trusted Signing (now known as Azure Artifact Signing). I had to send them my address and ID to get my identity verified so that I'd get approved for it.

Is there anything else I can do to put your mind at ease?

1 comments

Microsoft Trusted Signing only tells me you were able to get a key.

If this is intended to be an open source project, transparency would go a long way. The source code and actual history will make a big difference. If this is not intended to be an open source project, then hosting it on a source control system is misleading.

Not releasing source code is fine, but then you need to build trust. Is it paid software? Is there a company or a known name behind it (in which case, can you host it on that entity's website)? At minimum, toss up a website that describes what the software does, what the usage terms are, and whether it collects information about user systems and/or uploads data anywhere. Bonus, scan it with Windows Defender and a couple other malware scanners. Advertise that it scans clean.