Unsigned software
Posted: Sat Feb 12, 2022 3:15
Are there any plans of signing the executables you provide on your downloads page? Or at least to provide file hashes to verify you've downloaded untampered, official software?
fallout9 wrote:We will definitely inform the developer about it.
The warning you experienced indicates that the application had not established reputation with the Microsoft Defender SmartScreen Application Reputation feature at that time. We can confirm that the application vkbdevcfg-c.exe(sha256 –38a78d8bd4999649ae87e175ad1e429cce9239780dec897bf7f86d6aa02d4272) has since established reputation and attempting to download or run the application should no longer show any warnings.
Please note, however, that the submitted files are not signed using a valid digital certificate. Unsigned files will have to establish reputation each time a new version is released.
Application Reputation warnings are meant to indicate when applications do not have known positive reputation. This doesn’t mean that the application is malicious, only that it is “unknown.” Users can still proceed to download and run the application. If establishing reputation immediately is critical, you may want to consider investing in an EV Authenticode certificate.
A valid EV Authenticode certificate can immediately establish reputation with SmartScreen reputation services even if no prior reputation exists. In order to be considered a valid EV certificate, the certificate must be issued by a Certificate Authority that is authorized by the Microsoft Trusted Root Certificate Program and recognized as an Extended Validation issuer.
Thank you for contacting Microsoft.