Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

171–180 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#171

Earlier quoted context omitted.

I will personally pay you twenty thousand US dollars (in the cryptocurrency of your choice, bank transfer, western union, whatever) if you can prove beyond reasonable doubt that Microsoft has ever secretly shipped a backdoor in their OS so government agencies could spy on their users. Perhaps you will be the first person to actually prove the existence of the NSAKEY backdoor? (I doubt it.)

Why would this even be necessary to prove? At least for me that's not required, NSA_KEY plus Snowden leaks are enough. Microsoft is known to have no problems cooperating with governments requests, or how do you think they can operate all their services in China? Any hard evidence for such a backdoor wouldn't really change anything towards Microsoft for me.

If you believe the public information regarding _NSAKEY to be evidence of a backdoor, I’m sorry, but you are an idiot.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#172
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

Or maybe this is related to the security, and Windows is the only widely used platform that didn't enforce TPM until recently? macOS is even more locked down, but they don't impede or force users to use Mac App Store.

> but they don't impede or force users to use Mac App Store.

They briefly pulled Epic's desktop signing keys, which they promised were for security only, over an unrelated iOS business dispute.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#173
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

I saw the writing on the wall the moment they could sloppily justify the TPM requirement. Then I got into arguments with people proclaiming that it's just Microsoft enforcing it for the casual user's safety, and that I'm a Microsoft hater. Who? Me, whose first programming language was C#, who worked as an Windows server administrator for years, and my operating systems have been nothing than Windows for 2 decades. An…

I genuinely miss the days of playing with DOS, Windows 9x and then all the excitement of Windows XP. All on my own hardware, which was whatever I could scrape from parents, savings, neighbours. I could do what I wanted with these old PCs.

There was an openness that existed in the world of computing. Despite all that was said of Microsoft back then, and much of the complaints about proprietary software were true then also, it wasn't anywhere near as bad as this. Back then, new releases actually did improve my experience of computing.

Every time I use Windows 10 I feel like I'm constantly in battle with the PC. Every new piece of news I read, every new feature in software and now hardware I read and shudder, thinking, how much more of my privacy will it cost? What other aspect of my life is being invaded?

And because of the network effect, I'm trapped in their clutches. I have to use these services or I can't work, can't talk to friends. All well and good saying 'use Matrix' but a chat program with no friends is just a note taker.

Such a seismic shift and it was only two decades. I just want this hostility to end. A computer is a machine, which is an elaborate tool, for Pete's sake. I don't feel the same way towards my garden hose or washing machine.

(And I increasingly wonder, were we freer back then because there was still some empathy towards customer needs at Microsoft, or because they were simply stifled from their real intentions by technological limitations?)

Re: Microsoft no longer signs Windows drivers for Process Hacker

#174
post #29

Because of things like this, I'm at the point where I consider the invention of public-key encryption to be the worst thing that's ever happened to the world. If governments had _immediately_ preemptively classified anything related to assymetric encryption—and actively enforced the classified status—as soon as the first research into it started appearing, the world would be a much better place than it is now.

If you look at the history of encryption, thats preceisely what happened, and right up to the 90s they did contain it.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#175

Earlier quoted context omitted.

What popular end-user software cannot be installed and run with a mouse in e.g. Ubuntu?

The fact that you had to narrow it down to some arbitrary "popular" category to not touch the topic speaks for itself.

Alright then, what unpopular end-user software cannot be installed and run with a mouse in e.g. Ubuntu?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#176
post #66

Earlier quoted context omitted.

> Microsoft have their keys in the default keychain because they bothered to be involved in the process, unlike linux companies like Redhat. The status quo was that systems could boot any operating system the user wanted. Microsoft tried to force OEMs to lock operating systems other than those on a very short list (they tried to force Secure Boot to be enabled with no way for users to turn it off, and you can confirm…

There are two sides to this coin. Firstly there's the hardware vendors who make firmware, who decided to incorporate UEFI presumably because intel pushed it hard (original efi booted itanium and is also found in older Macs). But it was certainly possible for a Linux vendor to have got a key into the kek and dB lists: https://mjg59.dreamwidth.org/12368.html That's from Matthew Garrett, who along with Peter Jones, were…

> Microsoft's ARM hardware _is_ locked down with no such options

That was for 32-bit Windows on Arm hardware. 64-bit Windows on Arm laptops/tablets have unlockable Secure Boot, with a regular SETUP interface and all.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#177
post #96

Earlier quoted context omitted.

Yeah my thoughts! But on the other hand people also use Windows because its the default that comes with their new computer. (Not talking about HN community, talking about regular Joe) As long as Microsoft keeps lobbying OEMs to include Windows and there's no good alternative (looking at you, non-tech-savvy user-friendly Linux distros and major software vendors like Adobe, Autodesk etc, they will only keep locked to u…

>But on the other hand people also use Windows because its the default that comes with their new computer. True, but if Windows cannot run the application regular Joe wants, people will just switch to Chrome OS or Apple or Linux (wine?). Sometimes regular Joe's uses more exotic Software we can imagine, and they choose windows because it runs on it since 25 years. Just some examples i have seen: -VisualBasic 6 (for mo…

It's kind of a chicken-egg problem there too: Windows is the most ubiquitous OS when it comes to "computers" as the society knows, and more software gets written for it, and because of it, OEMs would prefer it even if MS doesn't push them anymore.

Not sure about the solution.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#178
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

Microsoft is doing its absolute best to move everyone to the Windows store by packaging the new apps everyone should be making into weird formats such as appx and msix which can't or previously couldn't be easily installed without command line funkiness. Luckily, Microsofts own incompetence is preventing this plan from working. There's another part to the exclusion of old hardware, which is that modern chips are a lo…

TPM, at least older version So it was/is recommended to use a pin/key and/or recovery key to ensure the security of the data. Unless your only threat model was to protect against common thievery and assume the attack had no technical prowess (and that’s perfectly fine, I do this for my company). Not to mention they were kinda used as a warranty canary for Truecrypt [2]. There were suspicions that nation states may have hardware bypasses worked out.

Later there were implementations of hardware encryption found to be vulnerable. So even now bitlicker does everything in software by default. [3]

So I understand why FOSS devs would rely more on standard practice (shared keys) with LUKS and not embrace hardware enclave options like TPM. They haven’t been the most reliable over the long term and are harder to patch/fix.

[1] https://pulsesecurity.co.nz/articles/TPM-sniffing

[2] https://threatpost.com/of-truecrypt-and-warrant-canaries/106...

[3] https://www.technadu.com/bitlocker-to-use-software-encryptio...

Re: Microsoft no longer signs Windows drivers for Process Hacker

#179
post #108
post #53

Earlier quoted context omitted.

"Dan would eventually find out about the free kernels, even entire free operating systems, that had existed around the turn of the century. But not only were they illegal, like debuggers—you could not install one if you had one, without knowing your computer's root password. And neither the FBI nor Microsoft Support would tell you that." --Richard Stallman, "The Right To Read"

Stallman was ALMOST right. The fight is not about which programs the user can run, but who controls the user data

He was early, but he wasn't wrong.

We are still headed directly to the place he described.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#180
Microsoft is locking certain API's:

Always-on-top, Auto-elevation, DPS statistics, Default taskmgr application preferences (Microsoft hardcoded taskmgr.exe blocking competitors), GPU statistics (deliberately broken on Win10 and Win11 recently) and the DirectUI framework are some examples of features that I want to implement and are currently implemented by Task Manager but are Microsoft-only signature restricted while newer more advanced security like PPL that we desperately need are also Microsoft-only signature restricted.

Post reply on HN