I’m developing a cross-platform desktop/mobile application for Windows, Linux, macOS, and Android.

My company already has an official digital certificate issued by Telekom. It is recognized for legally binding electronic signatures and document signing. In other words, the state recognizes the certificate and the identity behind it.

Yet that apparently isn’t enough for the major software platforms.

Apple wants an annual developer fee if I want normal macOS signing/notarization and distribution without scary warnings.

Google wants developers inside its Play Store ecosystem for normal Android distribution and updates.

Microsoft expects software publishers to use its accepted code-signing trust infrastructure, which usually means paying a commercial CA or using Microsoft’s own signing services if you want Windows to recognize the publisher without warnings.

So my question is: Why are these companies allowed to create their own private definition of “trusted developer,” even when a developer already possesses a legally recognized digital identity certificate?

I understand the technical argument that document signing and code signing are different certificate purposes. But from the developer’s perspective, the result looks like this:

“Your identity is legally verified, but we still won’t treat your software as trusted unless you participate in our approved ecosystem and, in many cases, pay.”

Why isn’t there a vendor-neutral mechanism where a legally recognized organizational certificate can establish publisher identity across operating systems? Is this mainly about security, liability, PKI design, platform control, commercial incentives, or some combination of all of them? And more importantly: what prevents Microsoft, Apple, and Google from abusing their position as platform owners to turn “trust” into a paid gatekeeping mechanism?

you are viewing a single comment's thread
view the rest of the comments
[–] 8 points 13 hours ago* (last edited 13 hours ago)

On its own, paying for verification isn't a bad thing. You pay, they do some work to confirm the app meets a certain standard, users can download apps with relatively low worries. It's dubious that they do a good job of verifying trust and safety at all, but conceptually it's not a bad setup.

The problem is when they also hold platforms and prevent alternative means of trust. Stuff like Steam and Epic? Whatever, they ask a fee for their store, if not worth it buy games elsewhere. But Apple? Our store or you can't run the app on your little computer. It's gross and unacceptable. Google really wants to be that too.

The justification is that a significant portion of users can't be trusted to make decisions about which software (distributors) to trust. Like yeah, I know it's pretty safe to download from F-Droid or install an app image or whatever from Blender's website. But imagine a scammer on the phone giving your grandfather instructions to install a keylogging bank app. To be fair, it is hard (if possible) to know what's really trustworthy once you get past mainstream app stores and applications.

But what prevents abuse from platform owners? Nothing, that's why they're actively abusing the trust they're given.

  • source