Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

161–170 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#161

Earlier quoted context omitted.

I find it interesting that, one one hand they are implementing features "in the name of security" that limit the owner of a computer what he/she can do with it and on the other hand they are adding backdoors so that government agencies (or anyone with right information) can spy on citizen that use this "secure" OS.

I will personally pay you twenty thousand US dollars (in the cryptocurrency of your choice, bank transfer, western union, whatever) if you can prove beyond reasonable doubt that Microsoft has ever secretly shipped a backdoor in their OS so government agencies could spy on their users. Perhaps you will be the first person to actually prove the existence of the NSAKEY backdoor? (I doubt it.)

Why would this even be necessary to prove? At least for me that's not required, NSA_KEY plus Snowden leaks are enough. Microsoft is known to have no problems cooperating with governments requests, or how do you think they can operate all their services in China?

Any hard evidence for such a backdoor wouldn't really change anything towards Microsoft for me.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#162
post #137
post #20

Earlier quoted context omitted.

SSH FS, a third-party extension seems to work well with VSCodium: https://github.com/SchoofsKelvin/vscode-sshfs

They mean Microsoft's plugins -- they just work with VSCode on purpose.

This one is an alternative to the remote development tooling which doesn't work on VSCodium. It is certainly not a full replacement, but you get to poke around the files on the remote system and run commands over SSH.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#163

Earlier quoted context omitted.

Apple could have done it with the Apple Silicon transition and yet didn’t. More inclined to believe actions over words at this point.

Not without massive loss of users. Both Microsoft and Apple would love to lock down their platforms, but they have to do it in tandem or users will flock to the other. So we will see a slow lock-in creep until they look like current day smartphones. Only way to stop this is to react strongly, so if most users are apathetic like you then it is inevitable. Of course I believe that you are right and most are this apathe…

Apathetic — no. I’m aware of the control creep in the industry, but I do think that it seems unnecessarily alarmist to think that Apple just can’t wait to lock down macOS. There is nothing to gain by them doing so and I would be incredibly surprised if they didn’t already know that.

iOS is and has always been a closed platform. We knew that the day they announced the first iPhone and they have been consistent in their messaging about that ever since. iPads and iPhones are globally successful though, far more so than the Mac, and with a far wider target audience that encompasses most people. It would be great for power users to be able to side-load without jailbreaking, but there are plenty of less technical people out there for whom side-loading actually presents much more of a risk than a benefit. That’s what makes it a complicated issue.

The Mac, on the other hand, doesn’t stand to benefit from that same closed model in the slightest. The real target audiences for the Mac (i.e. software developers, professional photography/cinematography, music production, publishing) all live and depend on software that requires flexibility, plugins etc and they stand a much greater chance of knowing what they’re doing. They would walk away from Macs in an instant if the platform stops being useful to them.

Apple Silicon was the perfect opportunity for Apple to close the platform if they really felt strongly enough to do so, but here’s the thing: Microsoft tried to do it with WinRT, it was an absolute disaster and the market spoke accordingly. It doesn’t seem worth the risk.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#165
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

Does a TPM chip actually bring any relevant security advantages for end users, or is it just for DRM?

It brings enormous security benefits to end users. TPMs drastically reduce entropy/complexity requirements for things like passwords/pins since the TPM can rate limit guess attempts. Doing that without a TPM is impossible since an attacker can always read the encrypted password off of the drive/directly from memory and then brute force it.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#166

Earlier quoted context omitted.

It's one command and you're forever in test mode[1], i.e.: don't enforce driver signatures: bcdedit /set testsigning on You just have to disable Secure Boot in UEFI first. (And I can confirm Windows 11 doesn't actually require Secure Boot to boot, I've had it off for months as part of win11 certification testing.) I'm not sure but DRM might revert to lower levels (e.g.: 720p), but that also happens on macOS when you…

One thing to note is that game anti cheats will just lock you out if you are in this mode. It’s the reason that game cheat makers look for exploits in random drivers to load their cheat in kernel space.

True, I forgot about that detail. Basically anything that relies on driver signing enforcement for security/privacy -- DRM, anti-cheats, specific proprietary algorithms -- will deactivate when test mode is enabled, whether one-time via the bootloader or set via bcdedit.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#167
post #108
post #53

Earlier quoted context omitted.

"Dan would eventually find out about the free kernels, even entire free operating systems, that had existed around the turn of the century. But not only were they illegal, like debuggers—you could not install one if you had one, without knowing your computer's root password. And neither the FBI nor Microsoft Support would tell you that." --Richard Stallman, "The Right To Read"

Stallman was ALMOST right. The fight is not about which programs the user can run, but who controls the user data

> The fight is not about which programs the user can run, but who controls the user data

Some things were so horrible, not even Stallman could imagine them happening in his worst nightmares.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#168
post #108

Earlier quoted context omitted.

Stallman was ALMOST right. The fight is not about which programs the user can run, but who controls the user data

Tell that to every iPhone app developer. It's worse than not having the right to execute. You can't even build the program you want. You have to use Apple pay, Apple subscriptions, Apple login. And you don't even get a relationship with your customer. Truly draconian.

And they tell me that automake is bad!

Re: Microsoft no longer signs Windows drivers for Process Hacker

#170
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

Microsoft is doing its absolute best to move everyone to the Windows store by packaging the new apps everyone should be making into weird formats such as appx and msix which can't or previously couldn't be easily installed without command line funkiness. Luckily, Microsofts own incompetence is preventing this plan from working.

There's another part to the exclusion of old hardware, which is that modern chips are a lot more reselient against crashes according to the telemetry Microsoft collects. The same is true for secure boot and other security lockdowns every Linux user disables. You could make the argument that this means that Microsoft is failing to provide stability for this older hardware, but it doesn't necessarily mean that it makes business sense for MS to put money and resources towards resolving the issue. Not making Windows 11 available on old chips doesn't hurt sales, helps them boast with great stability and security statistics and barely makes a dent in their reputation. Most people with a negative opinion of the company here were hating on Microsoft long before Windows 11 was even announced.

The TPM story makes sense from a Windows Hello standpoint. I don't think there's any doubt that the hardware trust system is more secure than the previous system. However, that trust is completely useless because Microsoft STILL doesn't enable Bitlocker unless you pay extra. It's current_year and Microsoft still hasn't brought data security to the masses. This is an area where proper use of the TPM can be benefit users massively.

Linux is having the exact opposite problem, I want to use my TPM and secure boot to leverage the hardware security built into my devices but it's as if every part of the Linux boot chain has implemented some kind of limitation to make the process difficult. Bitlocker works great, and I want it on Linux too, but nobody writing code for the Linux ecosystem seems to share my preferences here.

Post reply on HN