Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

231–240 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#231

Earlier quoted context omitted.

To give an example harm caused by the TPM / disk encryption feature in the consumer space: A recently-deceased friend's wife contacted me about getting personal data off from her late husband's computers. I ended up being able to get nothing for her. My friend, no doubt influenced by dementia and paranoia he was feeling, changed the passwords, made no note of them, and subsequently died. The computers in question run…

This is similar to why enabling 2FA actually scared the heck out of me! I use a password manager to generate strong unique passwords, so I think the chances of someone getting in that way are incredibly low. But I can absolutely see myself loosing all of my 2FA keys some day in a freak accident.

Nowadays the password managers can store the 2fa secrets and generate the codes as needed.

It kind of defeats the purpose of the second factor -- the password manager becomes it -- but at least it makes the services that insist on it happy.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#232
post #92

Earlier quoted context omitted.

Ofcourse they don’t force anything because of the competing windows platform which is more open up to now. Apple assumed market dominance and locked everything down on mobile. What I infer from your observation is that closing down Windows could also adversely affect Mac users, since Apple would not miss this opportunity.

> Apple assumed market dominance and locked everything down on mobile. Apple has about 26% market share on mobile globally, that's not exactly market dominance. Them locking down the platform limits piracy, which is one reason why developing for iOS is much more profitable for many kinds of apps, which causes better apps that drive consumers to the iPhone. That's the reason they put so much energy into locking down t…

I have to assume that them taking 75 percent of the profit in the smartphone industry, gives them a blank check to do as they wish, and the rest of the industry must follow.

https://www.counterpointresearch.com/global-handset-market-o...

Re: Microsoft no longer signs Windows drivers for Process Hacker

#233

Earlier quoted context omitted.

We have to disagree here. The threat models where the security that TPM offers are mostly applicable to the enterprise and business sectors where all devices on the network/AD/VPN have to be trusted and their storage encrypted. There TPM makes perfect sense. You average consumer/home user does not benefit at all from the features of TPM since they're not subject to the same threat model. Here TPM, and also stuff of t…

To give an example harm caused by the TPM / disk encryption feature in the consumer space: A recently-deceased friend's wife contacted me about getting personal data off from her late husband's computers. I ended up being able to get nothing for her. My friend, no doubt influenced by dementia and paranoia he was feeling, changed the passwords, made no note of them, and subsequently died. The computers in question run…

Did he enable a boot pin or are the drives just encrypted?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#234
post #214

Earlier quoted context omitted.

We have to disagree here. The threat models where the security that TPM offers are mostly applicable to the enterprise and business sectors where all devices on the network/AD/VPN have to be trusted and their storage encrypted. There TPM makes perfect sense. You average consumer/home user does not benefit at all from the features of TPM since they're not subject to the same threat model. Here TPM, and also stuff of t…

What about the scenario where your laptop is stolen and the attacker reads your data off the disk? All modern mobile devices protect against this scenario by default, but Windows devices required additional configuration to be protected. And in fact Secure Boot does protect against Grandma being infected by boot-time malware. And when has it ever been the case that it prevented you from installing Linux?

>And in fact Secure Boot does protect against Grandma being infected by boot-time malware.

And how can grandma get boot time malware at Home? IIRC those were common back in the days when people were plugging in infected floppy disks or thumb drives everywhere and you'd try to boot off them. Can't remember last time I saw this type of malware in the wild as phishing and ransomware is a lot more profitable for malicious actors than boot time malware.

>And when has it ever been the case that it prevented you from installing Linux?

This was always the case ever since secure boot launched and any OS that didn't have it's first stage bootloader signed by Microsoft could not boot. Even To this day, to install arch or puppy on my XPS i had to disable secure boot. Ubuntu and other major distros are fine here though but this gate keeping doesn't make it ok in my book.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#235
post #108
post #53

Earlier quoted context omitted.

"Dan would eventually find out about the free kernels, even entire free operating systems, that had existed around the turn of the century. But not only were they illegal, like debuggers—you could not install one if you had one, without knowing your computer's root password. And neither the FBI nor Microsoft Support would tell you that." --Richard Stallman, "The Right To Read"

Stallman was ALMOST right. The fight is not about which programs the user can run, but who controls the user data

It's both.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#236
post #214

Earlier quoted context omitted.

We have to disagree here. The threat models where the security that TPM offers are mostly applicable to the enterprise and business sectors where all devices on the network/AD/VPN have to be trusted and their storage encrypted. There TPM makes perfect sense. You average consumer/home user does not benefit at all from the features of TPM since they're not subject to the same threat model. Here TPM, and also stuff of t…

What about the scenario where your laptop is stolen and the attacker reads your data off the disk? All modern mobile devices protect against this scenario by default, but Windows devices required additional configuration to be protected. And in fact Secure Boot does protect against Grandma being infected by boot-time malware. And when has it ever been the case that it prevented you from installing Linux?

> And when has it ever been the case that it prevented you from installing Linux?

There was a window, when shim.efi was not signed.

> And in fact Secure Boot does protect against Grandma being infected by boot-time malware.

When it was the case that grandma was infected by boot-time malware? One-half-like malware happened decades ago, and under windows they need administrator rights anyway.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#237
post #108

Earlier quoted context omitted.

Stallman was ALMOST right. The fight is not about which programs the user can run, but who controls the user data

Tell that to every iPhone app developer. It's worse than not having the right to execute. You can't even build the program you want. You have to use Apple pay, Apple subscriptions, Apple login. And you don't even get a relationship with your customer. Truly draconian.

And we don't that to happen to Windows too.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#238

I know people who pretend that Nadella has made the company so different. Microsoft will never change.

It looked kind of promising for a while. With the pivot to cloud services, there was reason to hope they just would not care any more about pulling that kind of move for desktop Windows.

I guess after a decade of watching Apple and Google getting away with stuff that Microsoft would have been drawn and quartered for twenty years ago, they decided it was safe for them get back to their old ways.

sigh Would have been nice, though.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#239

Earlier quoted context omitted.

Have you ever considered that there's a huge amount of users that don't care about "graphics programming and usable UI/UX tooling"? Maybe Linux on the desktop doesn't suit your individual needs, but you seem awfully combative about it on the basis of your specific niche.

Some Linux Desktop are loudly combative about how great Linux Desktop is and seem to consider it some kind of failing if someone else doesn't agree. It's always "you chose the wrong distro!"[0] or "you have to be more picky with hardware!"[1], or even "it works for me, so you must be lying !". I imagine decades of experience with that person on internet forums is what has shaped parent's combativeness. [0] for litera…

> It's always "you chose the wrong distro!"

I know what you mean, but in this instance the complaint is poor UI/graphics while the distro in question is using a very cut-down desktop environment (running in a VM).

Re: Microsoft no longer signs Windows drivers for Process Hacker

#240
post #53
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

"Dan would eventually find out about the free kernels, even entire free operating systems, that had existed around the turn of the century. But not only were they illegal, like debuggers—you could not install one if you had one, without knowing your computer's root password. And neither the FBI nor Microsoft Support would tell you that." --Richard Stallman, "The Right To Read"

In a future where laws mandate signed software, the only way out is to somehow make our own hardware. We'll never be truly free unless we can manufacture free computers at home just like we can write free software at home. There is no software freedom if the processor refuses to run our code.

Right now the chip fabs require billions of dollars in investments in order to make our processors. They are single points of failure. There's nothing we can do if the government starts targeting them for regulation in order to curb effective cryptography, copyright infringement or any other subversive technology.

Post reply on HN