{"id":8847,"date":"2019-03-09T00:12:00","date_gmt":"2019-03-08T23:12:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=8847"},"modified":"2019-09-19T04:06:54","modified_gmt":"2019-09-19T02:06:54","slug":"notepad-developer-no-longer-ships-a-digital-signature","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/03\/09\/notepad-developer-no-longer-ships-a-digital-signature\/","title":{"rendered":"Notepad++: Developer no longer ships a digital signature"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">Don Ho, developer of Windows editor Notepad++, announced that he no longer digitally sign the code starting with version 7.6.4.<\/p>\n<p><!--more--><\/p>\n<p>Notepad++ is a highly popular open source text and source code editor for Windows. The code of this helpful tool has been digitally signed for the last 3 years by a donated DigiCert certificate. But now this certificate expires. Don Ho <a href=\"https:\/\/web.archive.org\/web\/20190624184940\/https:\/\/notepad-plus-plus.org\/news\/notepad-7.6.4-released.html\" target=\"_blank\" rel=\"noopener noreferrer\">wrote<\/a> in the release note for Notepad++ 7.6.4:<\/p>\n<blockquote>\n<p> When you install Notepad++ version 7.6.4, You might notice there's no more blue-trusted UAC popup.<\/p>\n<\/blockquote>\n<p>This is because Ho has removed the digitale signature from Notepad++ version 7.6.4. The reason for this decision has been explained as:<\/p>\n<blockquote>\n<p>3 years ago DigiCert donated a 3 years code signing certificate to the project, and every good thing has its end, the certificate has been expired since the beginning of this year. <\/p>\n<p>I was trying to purchase another certificate with reasonable price. However I cannot use \"Notepad++\" as CN to sign because Notepad++ doesn't exist as company or organization. I wasted hours and hours for getting one suitable certificate instead of working on essential thing &#8211; Notepad++ project.  <\/p>\n<p>I realize that code signing certificate is just an overpriced masturbating toy for FOSS authors &#8211; Notepad++ has done without certificate for more than 10 years, I don't see why I should add the dependency now (and be an accomplice of this overpricing industry). I decide to do without it.<\/p>\n<\/blockquote>\n<p>This move doesn't mean there's less security in Notepad++, because SHA256 hash of Installer and other packages will be provided for every release as usual. Notepad++ will check the SHA256 of all the components (SciLexer.dll, GUP.exe and nppPluginList.dll) used by the program. The only thing changed: There is now a yellow-orange UAC popup during installation, warning, that the program isn't digitally signed and asks, if the user trust that program. (<a href=\"https:\/\/www.bleepingcomputer.com\/news\/software\/notepad-no-longer-code-signed-dev-wont-support-overpriced-cert-industry\/\" target=\"_blank\" rel=\"noopener noreferrer\">via<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Don Ho, developer of Windows editor Notepad++, announced that he no longer digitally sign the code starting with version 7.6.4.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547],"tags":[69,1544],"class_list":["post-8847","post","type-post","status-publish","format-standard","hentry","category-security","category-software","tag-security","tag-software"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=8847"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/8847\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=8847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=8847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=8847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}