top | item 24282589

(no title)

aptgetrekt | 5 years ago

Microsoft isn't the only provider of certificates. It's more like the web where there are many authorities, not just one. If Epic were getting their cert from Microsoft and Microsoft retaliated to something Epic did with Fortnite on Xbox by revoking their certificate on Windows, Epic could just switch to a different provider for their EV cert.

The other difference is the message itself. Windows just displays a warning that the software couldn't be checked by smartscreen.[1] Once the app is used by enough people for the app to be in the smartscreen system the warning will disappear. Users will still see that the publisher is "unknown" though.[2] MacOS directs users to contact the developer that the app must be "updated" even if the only issue with the app is that it isn't notarized. A more fair message would be along the lines of "This app has not been notarized by Apple. Only run the application if you trust the source."

Code signing is intended to verify that the app actually came from who you think it came from. If the certificate for MS Word is unknown or something other than Microsoft you know something's not right and it's either been modified by a third party or not MS Word at all. Apple is using code signing to exert control over Epic Games rather than it's intended purpose to verify to MacOS users that their Unreal Engine in fact came from Epic.

1. https://www.ghacks.net/wp-content/uploads/2012/11/windows-10...

2. https://www.techspot.com/articles-info/1718/images/2018-10-0...

discuss

order

No comments yet.