Most posts here assume a web app: deploy, send a link, done. I ship a desktop app for Windows and macOS, and the part nobody warns you about is that a brand new signed binary is treated as guilty until proven otherwise.
On Windows, an Authenticode certificate is table stakes and still not enough. Reputation accrues per signing identity, over installs and over time, so a fresh release can throw "Windows protected your PC" at the exact moment a stranger first tries your product. That is the highest drop-off point in the entire funnel, and it fires on the people you worked hardest to get. The store listing never shows that prompt, which quietly turns store presence from a distribution channel into a trust workaround.
On macOS the equivalent is notarization plus whatever permission dialogs your features actually need. Anything that reads selected text or captures the screen has to ask for Accessibility and Screen Recording, and every one of those prompts is a place where someone can decide you are not worth it.
None of it is hard, exactly. It is weeks of work that produce no feature, it is invisible in every "I built and launched in a weekend" post, and it sits between download and first use, where your analytics probably cannot see it. A web app converts a click into a session. A desktop app has to convert a click into a download, an installer, an OS warning, a permission grant, and only then a session.
I am not arguing desktop is a mistake. The same friction is a moat once you are through it, and users who install something treat it differently from a tab.
But if you ship desktop, I would like to know what actually moved your install completion rate: signing, a store listing, changed copy on the download page, or something else entirely.