I’m developing a cross-platform desktop/mobile application for Windows, Linux, macOS, and Android.

My company already has an official digital certificate issued by Telekom. It is recognized for legally binding electronic signatures and document signing. In other words, the state recognizes the certificate and the identity behind it.

Yet that apparently isn’t enough for the major software platforms.

Apple wants an annual developer fee if I want normal macOS signing/notarization and distribution without scary warnings.

Google wants developers inside its Play Store ecosystem for normal Android distribution and updates.

Microsoft expects software publishers to use its accepted code-signing trust infrastructure, which usually means paying a commercial CA or using Microsoft’s own signing services if you want Windows to recognize the publisher without warnings.

So my question is: Why are these companies allowed to create their own private definition of “trusted developer,” even when a developer already possesses a legally recognized digital identity certificate?

I understand the technical argument that document signing and code signing are different certificate purposes. But from the developer’s perspective, the result looks like this:

“Your identity is legally verified, but we still won’t treat your software as trusted unless you participate in our approved ecosystem and, in many cases, pay.”

Why isn’t there a vendor-neutral mechanism where a legally recognized organizational certificate can establish publisher identity across operating systems? Is this mainly about security, liability, PKI design, platform control, commercial incentives, or some combination of all of them? And more importantly: what prevents Microsoft, Apple, and Google from abusing their position as platform owners to turn “trust” into a paid gatekeeping mechanism?

you are viewing a single comment's thread
view the rest of the comments
[–] 21 points 13 hours ago

Because document.certificates are not legal declarations. The only thing they do is add some confidence to the declaration that you already make just by offering a document.

Microsoft wants a higher quality and distinctly revokable certificate by default as a ward against malicious software. Users can absolutely ignore it or even trust a self-created certificate that you provide.

Apple, Google, Valve, Epic, Amazon, and also Microsoft charge a fee and/or a revenue cut to offer something for sale on their commerce platforms. Unlike Windows or Linux, "app stores" have potentially severe liability if malicious software is found on their platform, on top of other compliance costs, so they charge a fee to offset their risks or costs.


All of the above is mostly a pragmatic and economic argument. But you asked "why are they allowed", which presumes that there is some grand permission structure that has to assent before anyone can do anything. Which is not generally how the world works.

For most counties in the world, laws affecting private behavior only get passed to stop behavior that is already occurring. Since no one has passed a "think of the poor nerds" law prohibiting walled gardens in software, the gardens are free to exist and you are free to offer your work elsewhere.

  • source