OK Windows 10, we get it: You really do not want us to install this unsigned application. But 7 steps borders on ridiculous
- Reference: 1591349347
- News link: https://www.theregister.co.uk/2020/06/05/windows_10_microsoft_defender_smartscreen/
- Source link:
Tony Pottier is the developer of ImageView, an alternative to the Windows 10 Photos app for viewing images in a folder. The application is free and open source, but he [1]still has to pay for a code-signing certificate to avoid potential users being put off by warnings when they try to download and install.
Warning or preventing users from installing unverified applications is commonplace in today's operating systems, but does Windows go too far? We counted seven steps needed to download and install the open-source audio package [2]Ardour 6 , which is both unsigned and newly released, using the latest Edge and Windows 10.
The warnings start with the download itself. A message appears at the foot of the browser saying that the installer "was blocked because it could harm your device." A button to the right says "Delete". In order to download, a determined user has to go to the full download manager (if they can find it) where there is an option to "Keep".
[3]
Seven steps to installing an unsigned application on Windows 10
That is only the beginning. Next up is a dialog saying "This app might harm your device" with the option to "Delete" or "Cancel." This is really a dark pattern because if you click "Show more", it turns out there is another option, "Keep anyway". "Show different" rather than "Show more". Click that, and SmartScreen kicks in with another misleading dialog. "Microsoft Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk." The only button says: "Don't run," but once again, if you click "More info" you get a revised dialog with the option to "Run anyway."
After all that, User Account Control kicks in, coloured orange for warning, saying: "Do you want to allow this app from an unknown publisher to make changes to your device?" Only after again clicking "Yes" does the application install. If anything bad happens, you cannot say there was no warning.
Certifiable
It's a deterrent to installation for sure, but the whole rigmarole can largely be prevented by signing code with a certificate. Certificates for websites are easily obtained for free, but a code-signing certificate has to be purchased; GoDaddy, for example, will sell you one for £111.99 for a year at the time of writing. Pottier calls these "an overpriced piece of prime numbers generated by a computer," but because they both verify the publisher and show that the code is not tampered with, they make it possible for an application to be identified and trusted.
Pottier says that even the certificate is not enough. SmartScreen also uses a reputation database, and even a signed application starts from zero. Pottier was prevented from submitting an application to the new WinGet repository because it triggered a SmartScreen warning on this basis. It can only win reputation if it is downloaded some unspecified number of times, which is difficult if users are seeing the warnings that put them off.
A better solution is an EV (Extended Validation) code-signing certificate, which are around three times more expensive but appear to be fully trusted by SmartScreen. EV certificates include hardware tokens that are required for signing to reduce the likelihood of compromise. The cost is trivial for commercial or well-sponsored projects, but can be a problem for small developers.
Another open-source package, [4]Inkscape , is also offered for download unsigned. Developer Marc Jeanmougin [5]told us they don't bother to sign because "on Windows you can usually bypass all warnings." That said, the installer is signed for the Windows 10 Store and for macOS, where "we don't really have a choice."
Windows, as Jeanmougin observed, is relatively permissive despite the plethora of warnings. Apple's iOS only allows apps to be installed from its curated store. Windows Defender SmartScreen is inconvenient at times but that is less troublesome than a compromised PC. Microsoft is right in that an unsigned application could be tampered with and should not be trusted. If the industry could break the public habit of downloading any old application with a convincing web page wrapped around it, it would be good for security, though this is the not the only route by which malware can enter the system.
That said, the freedom to install software without bureaucracy, approval or extra expense is valued by many PC users and finding the right balance is difficult. It would help if Windows (like Linux on a Chromebook, which runs in a virtual machine) were better protected from badly behaved applications. [6]Windows 10X , perhaps, if and when it reappears. ®
[1] https://getimageview.net/2020/06/02/microsoft-defender-smartscreen-is-hurting-independent-developers/
[2] https://ardour.org/
[3] https://regmedia.co.uk/2020/06/04/steps.jpg
[4] https://www.theregister.com/2020/05/06/inkscape_v1/
[5] https://www.theregister.com/2020/04/14/16_years_inkscape_v1/
[6] https://www.theregister.com/2020/05/05/windows_10x_repurposed_for_single_screens/
Re: "This app may harm your device"
Dam, beat me to it. Have an up vote.
Re: "This app may harm your device"
Devices can be reinstalled and will be fine. It is us, the sorry folks "which do the computer thing", I worry about. What has been seen (er experienced, in this case), can not be made unseen. Though swiss chocolate and Islay malt seem to help (me, so far).
I thought containers were a thing now
Most applications don't need to open files except the ones the user chooses through a standard dialog box, or access random internet addresses without user interaction, or create dubious constantly-running background processes and "auto updaters", or silently raise their priority or privileges.
Computer science long ago reached the point at which it should be possible to run random applications that meet those criteria in a safe and secure manner. And indeed, that it should rarely be necessary to run applications that don't meet those criteria.
You'd think modern operating systems (and I'm not just looking at Windows) might possibly have caught up with this by now rather than desperately trying to patch up their 1960s pre-network, timesharing model of "security" with anti-virus software and code signing.
Re: I thought containers were a thing now
Have you tried Qubes? It's a hypervisor-as-OS concept, with each windown on your screen having an unforgeable coloured titlebar indicating which "domain" it is from. So my private GPG key is in a domain which doesn't have access to the internet or usb and none of the other domains have access to this domain's storage. I browse some of the more disreputable parts of a using a VM which disappears when I stop browsing. Intermediate levels are used for banking, work, and personal computing - have a play with it when you have a spare hour.
Re: I thought containers were a thing now
But the problem here is that the standard file selector dialogs just return a path and filename and let the application deal with them however it likes. Until those dialogs are changed to return objects that represent the files the user chose (and provide no other way to access the file system outside of the application's install and scratch directories) we are stuck with add-ons and workarounds to flawed security models.
So would Windows 10x be Windows 20 then?
does filter out friend&family support calls
The click 'more info' stage is going to stop most normal users, even if it wasn't deliberately low contrast and easy to completely miss it doesn't really hint it will bypass the block.
So many less friends & family demanding free computer servicing. I'll put up with the annoyance and Firefox skips the 1st half of the obstacle course anyway.
To be fair
Well, to be fair, everything in Windows 10 requires more steps than before. For instance, to set your default printer used to be start -> devices and printer -> right-click your printer and click set as default. Now ... start -> settings -> devices -> printers & scanners -> click your printer -> manage -> set as default printer -> yes to warning that Windows is no longer managing your default printer. What was once 4 clicks is now 8.
Re: To be fair
Yes, but if windows is managing it you don't need to go in there and set a default at all.
You just select the printer you ant to print from when you're printing and windows remembers that choice for future.
So really, 4 clicks has become 1 additional one within the print dialog.
Unless you want to manually change the default and not have windows manage it which you absolutely can do, but it's probably not the case for most users.
I am now Zen
I have WRT Windows 10 reached the same state as WRT Brexit: I am totally Zen. In both cases, after a lot of initial hand-wringing and a number of anguished nights, I have accepted the inevitable and simply tried to mitigate things as best as I could. In the case of Windows 10 that meant a switch to Linux... so now I can lean back and enjoy the show. As to Brexit... my OH is French and as things have turned out, we'll be fine whatever the shambles factory in No 10 decide to throw at us.
Hanlon's razor
Never attribute to malice that which is adequately explained by stupidity
While I personally believe that Microsoft have lost their way with Windows, as they seem hell bent on destroying a perfect reasonable operating system, I can't help wondering if there are some deeply dodgy business decisions being masked as incompetence. First they started removing non-MS programs with each 'update' and now they make it difficult to install them in the first place - or rather impossible for the less tech savvy. Next they'll be demanding that we rent our operating system and applications for a modest 30% cut.
Is is just corporate culture? Extinguish the competition? Make the plebs pay because we *need* our billions?
I too abandoned Win10 and switched to Linux because I'm able to. My friends have ended up with iPads.
I will decide what I run on my computer thank you very much.
...because if I don't then somewhere down the line will come the "I'm sorry, this developer hasn't paid sufficient tribute for you to install this application - you will use one of the pre-selected highly profitable (for us) alternatives". They can dress that in whatever language they want, but that's what the popup will actually say, and small development houses and open source projects will be snuffed out. No, you can't use this perfectly good free application, you're going to $CORPORATION and you're installing their awful bloated, add infested, spyware infested "alternative" because they paid to get in this store, and the foss project didn't.
I'm having none of it.
(Finally massively lost my temper with Windows and binned it at home last month. It's still on my 2nd disk in the assumption that I will eventually want to play DooM Eternal, but thus far I've actually not wanted to have to deal with the annoyance of booting Windows again to *do* that)
"This app may harm your device"
Should first come up when you try to install Windows 10.