Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

151–160 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#151
post #66
post #23

The article mentions Process Explorer. Since Sysinternals were bought by Microsoft many years ago and the tools are distributed directly via Microsoft, such tools are unlikely to have an issue being signed. A brief history of the process for those not following it. Originally for kernel-mode drivers, you needed a code signing certificate cross signed by Microsoft's root . This means that the certificate follows a cha…

> Microsoft have their keys in the default keychain because they bothered to be involved in the process, unlike linux companies like Redhat. The status quo was that systems could boot any operating system the user wanted. Microsoft tried to force OEMs to lock operating systems other than those on a very short list (they tried to force Secure Boot to be enabled with no way for users to turn it off, and you can confirm…

There are two sides to this coin. Firstly there's the hardware vendors who make firmware, who decided to incorporate UEFI presumably because intel pushed it hard (original efi booted itanium and is also found in older Macs).

But it was certainly possible for a Linux vendor to have got a key into the kek and dB lists: https://mjg59.dreamwidth.org/12368.html

That's from Matthew Garrett, who along with Peter Jones, were responsible for the first shim.

A central authority like the Linux foundation could have stepped up here and could have since, actually. I understand why fedora/redhat preferred not to be in a privileged position but I can't help but feel someone ought to have stepped up.

The other side of the coin is the windows logo program, that requires secure boot be turned on by default. For x86 I'm fairly sure it also requires that the user can take control of the platform key and therefore evict Microsoft keys from the firmware. It also requires that secure boot should be disabled. I'm fairly sure Microsoft did this because they realised there would be objections otherwise

Microsoft's ARM hardware _is_ locked down with no such options and I object to that wholeheartedly. But then I also don't buy Apple kit for daily driver use for the same reason. Also luckily Microsoft are currently irrelevant in the arm space, although that might change with the serverready profiles.

I am sure the process was onerous, but someone could have done it. Linux is big business in the server hardware space and intel for example contributed the thunderbolt code to the kernel. I am fairly sure they could between them organise a foundation and throw a few 100ks per year at maintaining a signing key for other distros independently to Microsoft.

I don't believe any entirely locked down firmware ever made it into any x86 board.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#152
post #108
post #53

Earlier quoted context omitted.

"Dan would eventually find out about the free kernels, even entire free operating systems, that had existed around the turn of the century. But not only were they illegal, like debuggers—you could not install one if you had one, without knowing your computer's root password. And neither the FBI nor Microsoft Support would tell you that." --Richard Stallman, "The Right To Read"

Stallman was ALMOST right. The fight is not about which programs the user can run, but who controls the user data

Tell that to every iPhone app developer.

It's worse than not having the right to execute. You can't even build the program you want. You have to use Apple pay, Apple subscriptions, Apple login. And you don't even get a relationship with your customer.

Truly draconian.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#153
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

I find it interesting that, one one hand they are implementing features "in the name of security" that limit the owner of a computer what he/she can do with it and on the other hand they are adding backdoors so that government agencies (or anyone with right information) can spy on citizen that use this "secure" OS.

I will personally pay you twenty thousand US dollars (in the cryptocurrency of your choice, bank transfer, western union, whatever) if you can prove beyond reasonable doubt that Microsoft has ever secretly shipped a backdoor in their OS so government agencies could spy on their users.

Perhaps you will be the first person to actually prove the existence of the NSAKEY backdoor? (I doubt it.)

Re: Microsoft no longer signs Windows drivers for Process Hacker

#154
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

I saw the writing on the wall the moment they could sloppily justify the TPM requirement. Then I got into arguments with people proclaiming that it's just Microsoft enforcing it for the casual user's safety, and that I'm a Microsoft hater. Who? Me, whose first programming language was C#, who worked as an Windows server administrator for years, and my operating systems have been nothing than Windows for 2 decades. An…

And they will get away with it. The generation that grew up with smartphones primarily, getting a computer only later on (if at all) will find this totally normal. Even Android is getting locked up more and more over the couple last releases too, even most Chinese vendors stopped letting you unlock the bootloader, and nobody complained.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#155
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

> In related news - ever wondered why Windows 11 can't be installed on "older computers"?

Except of course some older Surface line hardware, because why even be subtle?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#156
post #127

Earlier quoted context omitted.

>I saw the writing on the wall the moment they could sloppily justify the TPM requirement. Microsoft doxed itself on the TPM limitation being purely arbitrary when Windows 11 compatibility checks passed on a Pentium 4 CPU and installed just fine due to a mistake from Microsoft where they forgot to blacklist that CPU family lol. https://twitter.com/Carlos_SM1995/status/1448561898035851264...

>purely arbitrary As if years of experience hasn't taught us that opt-in security is stupid. This would be arbitrary if the TPM was useless, but it isn't.

We have to disagree here. The threat models where the security that TPM offers are mostly applicable to the enterprise and business sectors where all devices on the network/AD/VPN have to be trusted and their storage encrypted. There TPM makes perfect sense.

You average consumer/home user does not benefit at all from the features of TPM since they're not subject to the same threat model. Here TPM, and also stuff of the UEFI security chain like Management Engine and Secure Boot in the past, act more like hostile wall-gardening that limit what a user can install on his system (remember how enabling secure boot originally meant you couldn't install any linux distro?) rather than add any meaningful security (will TPM and Secure Boot prevent grandma from getting her PC infected by malware off some shady phishing site? No? Then don't force those requirements for private users)

Re: Microsoft no longer signs Windows drivers for Process Hacker

#157
post #92

Earlier quoted context omitted.

Or maybe this is related to the security, and Windows is the only widely used platform that didn't enforce TPM until recently? macOS is even more locked down, but they don't impede or force users to use Mac App Store.

Ofcourse they don’t force anything because of the competing windows platform which is more open up to now. Apple assumed market dominance and locked everything down on mobile. What I infer from your observation is that closing down Windows could also adversely affect Mac users, since Apple would not miss this opportunity.

> Apple assumed market dominance and locked everything down on mobile.

Apple has about 26% market share on mobile globally, that's not exactly market dominance.

Them locking down the platform limits piracy, which is one reason why developing for iOS is much more profitable for many kinds of apps, which causes better apps that drive consumers to the iPhone. That's the reason they put so much energy into locking down the platform

Re: Microsoft no longer signs Windows drivers for Process Hacker

#158

Earlier quoted context omitted.

There is also one reason many here don't see: you don't have to bother with the console. Everything can be installed and run with a mouse. Don't take me wrong. I understand the good sides of console programs. You can do a lot there but your average user doesn't care.

What popular end-user software cannot be installed and run with a mouse in e.g. Ubuntu?

The fact that you had to narrow it down to some arbitrary "popular" category to not touch the topic speaks for itself.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#159
post #57

An immensly powerful and useful tool. Can't live without it. Hopefully the situation resolves soon. What is it with MS these past few months? It's like they're trying to throw away the little community goodwill they managed to build up over the years.

Quite a lot of community goodwill, unfairly granted. I've lost count of how many times I've read on this very forum, "calling it Micro$oft is childish, they're a changed company, Nadella is better than Ballmer, etc". They are as hostile to free software as they ever were. Why wouldn't they be? It's antithetical to their business model. The only thing that's changed is how sneaky they are about their time-honored tact…

Microsoft took the same approach as Bill Gates. Gate's ruthlessness made the public hate him(remember the milkshaking?). He took public relations serious and put on the nice guy public facing image while still being as devious and wretched as he was back then. The Microsoft leaders saw how well this worked him and used the same tactic.
Post reply on HN