logoalt Hacker News

Frotagtoday at 4:49 PM2 repliesview on HN

Conveniently M$ lets you buy a signing certificate to fix this.

https://stackoverflow.com/questions/48946680/how-to-avoid-th...


Replies

pimterrytoday at 5:17 PM

EV no longer skips smartscreen either nowadays. I understand that was abused, so it's treated as the same as OV. Having a certificate allows the cert itself to accumulate trust (rather than each binary independently doing so) and provides better UX and I suspect an initial small boost to trust signal, but doesn't bypass the initial distrust. There's no way to avoid that AFAICT and even if you're an established business you hit it at intervals because all these certificates expire and so the whole process resets every few years anyway. What a mess.

show 3 replies
asveikautoday at 4:51 PM

Last I checked they can still quarantine your binary if it's properly signed and they decided it hasn't gained traction.