Even more lols when you are gigabyte and your private key leaks. Also when you are gigabyte and your signed driver is used to privilege escalate malware.
And that’s why certificates can be revoked, that’s the whole point, trust. It only costs a few hundred a year per Microsoft’s documentation and approved vendors so it doesn’t seem that much of an ask. At the very least you can look up the developer yourself, harder to do if the package has no identity associated with it
I wrote some open source software and looked into how to make that not happen. It’s not easy on Microsoft, and on Apple it costs more than a $100/year!
Not only that; You have to pay for updates too. Supposedly it’s because Apple takes time to verify that the app is legit and not going to do nefarious things. So they don’t want a bad actor to get a legit app on the store, then later push an update that infects everyone with a virus.
But apparently a company did a study and realized that app testing rarely made it past the main page, with testers spending ~15-20 seconds per app. They’d basically open it and if it looked like it did what it said, they didn’t bother digging any deeper.
They basically admitted at a security conference (I think) that part of the roadmap for Windows 11 is to actually prevent Windows from running unsigned apps period, and you better believe getting past that will require an Enterprise license.
I definitely need a source on this. I searched online and couldn't find anything. If this is true, I feel like it's the one thing that might actually cause some people to move to Linux.
I can navigate Windows well enough for my job, but I'd never choose it for personal use. I'm no Linux expert, but I haven't yet been faced with a problem I couldn't solve.
I was taught to use Ubuntu Linux by a middle aged engineer in another field who demanded "the brown operating system" on his computer over a decade ago, so yes, I agree, day to day Linux hasn't been hard for over a decade.