Hi,
First of all, it is correct that this raises your suspicion, and it shows that you care about software integrity. In this particular case, there is fortunately nothing to worry about.
To address this publicly to ease your concerns: This is correct. The valid and safe official Zettlr binaries for Windows currently ship with a certificate issued to "Benjamin Milburn-Town" instead of me. This is expected and correct.
Background:
I use Microsoft Azure for Code signing, but since Microsoft has unfortunately decided not to let any private individuals from Europe sign up for code signing, I was unable to retrieve a new certificate after the old one (which was on my name) expired. Thankfully, contributor benniekiss (GitHub; crusible on Discord) has agreed to provide their legal name instead for this certificate since they are a legal resident of the United States.
The previous discussion was led in this issue, and I have updated this forum discussion accordingly.
Some notes:
- Each identity validation is valid for only one year. The current validation will expire some time in the Spring of 2027.
- I will attempt to associate the certificate back to my name again to reduce confusion. However, if Microsoft does not change their terms and still barr European individuals from perusing their certificate service, we may continue to stick to their help.
- In any case, I wish to cross this bridge when we get there, because it is not efficient to be worried about this right now.
- I will again be announcing any changes here on the Forum, on GitHub, and on Discord, as I did with the last certificate change.
In any case, let me reiterate that I believe it is a good habit to be vigilant.