Microsoft no longer signs Windows drivers for Process Hacker
21–30 of 543 posts
Re: Microsoft no longer signs Windows drivers for Process Hacker
#22An immensly powerful and useful tool. Can't live without it. Hopefully the situation resolves soon. What is it with MS these past few months? It's like they're trying to throw away the little community goodwill they managed to build up over the years.
> What is it with MS these past few months? I was thinking the same. It's not been a good few weeks for them. They're quickly losing trust which was hard to acquire in the first place given their history. Maybe a timely reminder to mention Halloween [1] ? [1] https://en.wikipedia.org/wiki/Halloween_documents
- rebrand as open-source friendly, only open-source whatever narrow side-projects they barely care about but could be run on other systems (VSCode, Powershell); distribute official packages with spyware
- monopolize the education system by offering bribes including gratis hardware devices to whoever in State education will work with them to pretend Microsoft loves kids and kids need computers (with Microsoft software, obviously) to learn anything in the 21st century
- force manufacturers to deploy "TPM v2.0" on their new machines so they can run Windows 11, continuing the push so that people have 0 understanding and control over the machines they own (instead are controlled by the machines), and don't have a choice of system because "SecureBoot" [0]
- love Linux! let them integrate all your POSIX/Linux APIs in a VM on their system, so that you never have to use anything else than Windows ever again (embrace...) ; it's just like reverse-Wine (execute Windows program on free systems) except they have an army of developers with $$$$ and don't have to waste time reverse-engineering anything because they have the source code to both systems... how convenient!
- viruses are such a huge problem, if only we had some sort of digital signatures for software, and trustworthy places to get it from?! sure let's have a Microsoft market where you can buy adware/spyware signed by Microsoft, with two key advantages: 1) it's super faster because signed software is not inspected real-time by Windows defender 2) noone else can make their own "appstore" repository with their own signature keys (like we do with Flatpak/APT/nix/guix) ; very soon they can start to hide how to run programs unapproved by Microsoft like Android or MacOS [1] have been doing... and it's all for security, right? because app-store monopoly has definitely stopped malware (oooh that's a nice flashlight app you got there Google Play) without harming FLOSS/hobbyist devs (yeah sure)
It's just *washing (openwashing here) straight out of marketing textbooks. If you know/learn anything about capitalism and public relations, you won't be tricked next time!
[0] Briefly touched upon in this bigger article about how Microsoft is still evil, why Secure Boot has nothing to do with security, and why hardware manufacturers happily play along: https://www.haiku-os.org/blog/mmu_man/2021-10-04_ok_lenovo_w...
[1] There was even this worrying story at some point that MacOS would refuse to open applications (whether signed or not) because their centralized server could not be reached: https://news.ycombinator.com/item?id=25074959 <-- Soon coming to your Windows setup
Re: Microsoft no longer signs Windows drivers for Process Hacker
#23A brief history of the process for those not following it. Originally for kernel-mode drivers, you needed a code signing certificate cross signed by Microsoft's root. This means that the certificate follows a chain up to a standard CA _and also_ one Microsoft use to approve that CA to issue kernel-mode certificates. It was not sufficient to have a certificate capable of signing code, even with MS' OIDs for that.
Then, around Windows 10 I think, Microsoft announced that one would need to acquire an EV certificate. You would then be required to submit the driver package via sysdev.microsoft.com and after spending time in Ballmer's Brewery, it would come out signed by Microsoft.
It was technically possible to use the old mechanism at this stage too, provided the end user did not have UEFI secure boot enabled. IF secure boot were enabled, the kernel would: a) if the driver was signed pre-Win10, accept it, b) if it was signed post win-10 RTM date and by Microsoft, accept otherwise reject.
Thus the only mechanism to realistically get your driver working on all Windows out of the box is to submit via sysdev. You can't realistically ask users to disable secure boot, even if this is entirely possible on all x86 motherboards.
Finally, the cross signed roots expire soon and I think some already have. Microsoft have decided that this mechanism will now be retired, and all drivers must be signed via sysdev from now on. You still require an EV certificate as well, to sign the package.
This is a bit of a mixed bag. On the one hand, Microsoft have repeatedly signed the shim maintained by redhat in order to allow Linux distributions to boot directly on secure boot-enabled hardware (UEFI binaries also go through this process and always have). Microsoft have their keys in the default keychain because they bothered to be involved in the process, unlike linux companies like Redhat. So on the one hand, they're being quite friendly to open source.
On the other hand, the push to EV certs rules out individual developers like myself[1]. I could register a company but... that entails effort and expense for a hobby project. And now hobbyist projects like this run the risk of being rejected by MS.
I mostly believe this is an attempt to reduce the number of code signing cert leaks that result in people writing malware, and lock down the Windows kernel a bit more, but still. It is a shame.
[1] This is because most CAs won't issue EV certificates to individuals, even if those individuals happen to have detailed knowledge of cryptography and all the pkcs.
Re: Microsoft no longer signs Windows drivers for Process Hacker
#24Re: Microsoft no longer signs Windows drivers for Process Hacker
#25You know, the ones that don't have a TPM chip?
Now you know. Windows 11 completes the lock-up of the OS.
That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increase. Against older promises of W10 being the last Windows version ever.
Welcome to the future that Microsoft always wanted, but couldn't have - a platform with airtight control. Just like what Apple has with its AppStore and its wonderful, wonderful 30% commission. Almost there and the lemmings didn't even notice it, distracted by the new and friendly Microsoft front, free upgrades to Windows 10 and centered Start menu in Windows 11.
Mark my words - Windows 12 will severely impede direct installation even of an user-space software, funnelling everyone to go through the store. That's the end goal and we will all be there in a couple of years, whether we want it or not.
Re: Microsoft no longer signs Windows drivers for Process Hacker
#26In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…
Re: Microsoft no longer signs Windows drivers for Process Hacker
#27> Microsoft Process Explorer has the same functionality so they don't have standing to block competitors then go and include the exact same features in their own software. > Microsoft has been secretly adding more powerful features than Process Hacker via their SAC product – SAC has no security whatsoever by design – they're clearly targeting the project not because of any actual technical issues but rather because w…
Re: Microsoft no longer signs Windows drivers for Process Hacker
#28Earlier quoted context omitted.
> What is it with MS these past few months? I was thinking the same. It's not been a good few weeks for them. They're quickly losing trust which was hard to acquire in the first place given their history. Maybe a timely reminder to mention Halloween [1] ? [1] https://en.wikipedia.org/wiki/Halloween_documents
They've always been acting as a strong monopolistic corporation with a "fuck you" attitude. Here's a summary of Microsoft attitude these part 5 years: - rebrand as open-source friendly, only open-source whatever narrow side-projects they barely care about but could be run on other systems (VSCode, Powershell); distribute official packages with spyware - monopolize the education system by offering bribes including gra…
Yeey, brave new megacorp world!
Re: Microsoft no longer signs Windows drivers for Process Hacker
#29If governments had _immediately_ preemptively classified anything related to assymetric encryption—and actively enforced the classified status—as soon as the first research into it started appearing, the world would be a much better place than it is now.
Re: Microsoft no longer signs Windows drivers for Process Hacker
#30In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…
Microsoft really thinks they can compete with platforms like android or iOS, i have to say: Thank you Microsoft!! You accelerate the downfall of Windows! No one will need you in the future, Adobe on M1(Apple), Development on Linux, Gaming on Linux, Workstations Linux maybe some Apple.