I’m developing a cross-platform desktop/mobile application for Windows, Linux, macOS, and Android.

My company already has an official digital certificate issued by Telekom. It is recognized for legally binding electronic signatures and document signing. In other words, the state recognizes the certificate and the identity behind it.

Yet that apparently isn’t enough for the major software platforms.

Apple wants an annual developer fee if I want normal macOS signing/notarization and distribution without scary warnings.

Google wants developers inside its Play Store ecosystem for normal Android distribution and updates.

Microsoft expects software publishers to use its accepted code-signing trust infrastructure, which usually means paying a commercial CA or using Microsoft’s own signing services if you want Windows to recognize the publisher without warnings.

So my question is: Why are these companies allowed to create their own private definition of “trusted developer,” even when a developer already possesses a legally recognized digital identity certificate?

I understand the technical argument that document signing and code signing are different certificate purposes. But from the developer’s perspective, the result looks like this:

“Your identity is legally verified, but we still won’t treat your software as trusted unless you participate in our approved ecosystem and, in many cases, pay.”

Why isn’t there a vendor-neutral mechanism where a legally recognized organizational certificate can establish publisher identity across operating systems? Is this mainly about security, liability, PKI design, platform control, commercial incentives, or some combination of all of them? And more importantly: what prevents Microsoft, Apple, and Google from abusing their position as platform owners to turn “trust” into a paid gatekeeping mechanism?

all 12 comments

sorted by: hot top controversial new old
[–] 13 points 8 hours ago

Because nobody's enforcing antitrust law to stop them.

  • source
  • [–] 59 points 12 hours ago

    Nothing prevents them abusing their dominant positions in their respective market segments. As you have observed. None of that stuff would exist otherwise. They are trying to put an end to the once-popular idea of open platforms, because they now feel that they have enough power to get away with it.

  • source
  • [–] 15 points 10 hours ago

    Why are these companies allowed to create their own private definition of "trusted developer"?

    Lots of reasons. The reason these platforms will give will be something along the lines of "to make sure that the developer is trusted we need to verify them and that costs money". I personally believe it's just that they want your money, and I personally believe this is monopolistic behavior. In a working system that's for the FTC to investigate.

  • source
  • [–] 29 points 12 hours ago

    Simple answer...they are monopolists and currently have us all by the throat because of limited options.

  • source
  • [–] 27 points 12 hours ago (1 child)

    Why does the mob charge for protection?

  • source
  • hideshow 1 child comment
  • [–] 21 points 12 hours ago

    Because document.certificates are not legal declarations. The only thing they do is add some confidence to the declaration that you already make just by offering a document.

    Microsoft wants a higher quality and distinctly revokable certificate by default as a ward against malicious software. Users can absolutely ignore it or even trust a self-created certificate that you provide.

    Apple, Google, Valve, Epic, Amazon, and also Microsoft charge a fee and/or a revenue cut to offer something for sale on their commerce platforms. Unlike Windows or Linux, "app stores" have potentially severe liability if malicious software is found on their platform, on top of other compliance costs, so they charge a fee to offset their risks or costs.


    All of the above is mostly a pragmatic and economic argument. But you asked "why are they allowed", which presumes that there is some grand permission structure that has to assent before anyone can do anything. Which is not generally how the world works.

    For most counties in the world, laws affecting private behavior only get passed to stop behavior that is already occurring. Since no one has passed a "think of the poor nerds" law prohibiting walled gardens in software, the gardens are free to exist and you are free to offer your work elsewhere.

  • source
  • [–] 16 points 12 hours ago

    Why isn’t there a vendor-neutral mechanism where a legally recognized organizational certificate can establish publisher identity across operating systems?

    A few reasons.

    The more altruistic reason is that the app store is running under the company's brand and what is let on the app store can be seen as a reflection of that brand's values. Hence things like the porn ban on iOS. It is implied that the app store has some responsibility for the content hosted.

    The more realistic reason is money. App stores have become the main revenue source for several operating systems. No large company is going to give up that revenue stream.

  • source
  • [–] 17 points 12 hours ago

    Because they are monopolies in their own areas.

  • source
  • [–] 8 points 12 hours ago* (last edited 11 hours ago)

    On its own, paying for verification isn't a bad thing. You pay, they do some work to confirm the app meets a certain standard, users can download apps with relatively low worries. It's dubious that they do a good job of verifying trust and safety at all, but conceptually it's not a bad setup.

    The problem is when they also hold platforms and prevent alternative means of trust. Stuff like Steam and Epic? Whatever, they ask a fee for their store, if not worth it buy games elsewhere. But Apple? Our store or you can't run the app on your little computer. It's gross and unacceptable. Google really wants to be that too.

    The justification is that a significant portion of users can't be trusted to make decisions about which software (distributors) to trust. Like yeah, I know it's pretty safe to download from F-Droid or install an app image or whatever from Blender's website. But imagine a scammer on the phone giving your grandfather instructions to install a keylogging bank app. To be fair, it is hard (if possible) to know what's really trustworthy once you get past mainstream app stores and applications.

    But what prevents abuse from platform owners? Nothing, that's why they're actively abusing the trust they're given.

  • source
  • [–] 9 points 12 hours ago*

    abusing their position as platform owners to turn “trust” into a paid gatekeeping mechanism?

    It's not about trust. It is a paid gatekeeping mechanism. Apple got away with it and everyone copied Apple. Microsoft was the last commercial hold out thinking people didn't want to be controlled. Boy were they wrong.

  • source
  • [–] 7 points 12 hours ago

    Because they own their respective platforms thus can dictate how it's used.

    And the fees were initially to get rid of scammers. Android long ago had a completely free dev experience, from project scaffolding to delivery to users. And it was abused a LOT - the early app market/marketplace (prior to the Play rebrand) was teeming with apps that had malware or other malicious code embedded.

    The thing is, all of these companies forgot that the monies paid by the developers after income or just plain publishing, is for the upkeep of the store and its related services. Now it's being treated as its own income source, because of course capitalism won't allow for a branch of a company to exist that doesn't directly generate revenue...

  • source