Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why bother checking the signature of dependencies if the main executable integrity isn't being checked?

What really surprises me is that the author of something as great as Notepad++ isn't making enough money from the project to easily be able to pay for the certificate.



It's not about the price, but about name on the certificate:

> However I cannot use "Notepad++" as CN to sign because Notepad++ doesn’t exist as company or organization

CAs would put author's name as CN, which isn't great, especially for collaborative project.


Yep and sometimes the name people know isn't the name that a CA will permit in a certificate. I have one of those. I'm known as a shortened version of my middle name, say Jack Quimby, but DigiCert and others insist that the cert be issued to Alphonse Jackson Quimby, Jr.

OK I'll just buy an LLC from a state that's cheap (never mind the paperwork) but that's no good either because the new entity had no listed phone number...


>OK I'll just buy an LLC

When I bought code signing certificate for my LLC, in their infinite wisdom CA put "Spółka z ograniczoną odpowiedzialnością" as CN, because that's what they saw on proof of ownership. "Spółka z ograniczoną odpowiedzialnością" literally means "Limited liability company" in Polish.


But they "spend hundreds" on checking the validity of the requester.


I know that must have been a pain in the neck for you, but that's hilarious. Thanks for sharing!


Then I think you'll find this Poland-related story amusing too: http://news.bbc.co.uk/2/hi/uk_news/northern_ireland/7899171....


I love it.


That doesn't seem like it should be a deal breaker, especially for something security related.


Could be related to the CIA replacing common libraries with their own.

https://notepad-plus-plus.org/news/notepad-7.3.3-fix-cia-hac...


Price doesn't seem to be his primary issue.


I suppose we could all demand a refund.

Edit: downvoted? The project is GPL, not a revenue source.


The opposite would surprise me. How would Notepad++ earn any money?


Redhat is an example of a company that makes money on top of extensive open source contributions. I doubt a similar model would work for a text editor. There is a reason most open source projects like this have a corporate benefactor.


Context aware ads




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: