Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

291–300 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#291

Earlier quoted context omitted.

>The fight is not about which programs the user can run, but who controls the user data But the user data is mostly in the cloud, owned by Apple, MS, Google, Amazon, Facebook. In the future we will be lucky to have apps that work offline with local data.

"In the future we will be lucky to have apps that work offline with local data. " Are you from the past? This here is 2021. And right here, the expensive, professional apps still lets you grudgingly do it, but small/casual apps that work really offline? That became rare. Usually it is mainly server and some local cache, you better take care of, if you are in an area with bad connection. But more and more of my peers…

Spotify works fine offline, you just have to download the tracks ahead of time.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#292

From: https://github.com/processhacker/processhacker/discussions/7... >The existing drivers are compatible with Win11 and haven't been blocked by Microsoft yet... The large majority of changes by Microsoft are limited to restricting the Windows API with signature checks that block competitors software (e.g. CreateWindowInBand, NtQuerySystemInformation, NtQueryInformationProcess to name a few) rather than directly tar…

> So, basically, for some reason, Microsoft wants to make it very hard for you to see whats running on your computer...

That's my take on it, too. I doubt they care about a "competing" task-manager tool.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#293

Earlier quoted context omitted.

> Apple assumed market dominance and locked everything down on mobile. Apple has about 26% market share on mobile globally, that's not exactly market dominance. Them locking down the platform limits piracy, which is one reason why developing for iOS is much more profitable for many kinds of apps, which causes better apps that drive consumers to the iPhone. That's the reason they put so much energy into locking down t…

Locking things down and snooping are always presented as an advantage. Stoping piracy, stoping CP, stoping drug dealers and so on. Maybe we should have some company lock us in our houses for safety? You know, if you wander outside you might get robbed.

[deleted]

Re: Microsoft no longer signs Windows drivers for Process Hacker

#294

Earlier quoted context omitted.

I saw the writing on the wall the moment they could sloppily justify the TPM requirement. Then I got into arguments with people proclaiming that it's just Microsoft enforcing it for the casual user's safety, and that I'm a Microsoft hater. Who? Me, whose first programming language was C#, who worked as an Windows server administrator for years, and my operating systems have been nothing than Windows for 2 decades. An…

I genuinely miss the days of playing with DOS, Windows 9x and then all the excitement of Windows XP. All on my own hardware, which was whatever I could scrape from parents, savings, neighbours. I could do what I wanted with these old PCs. There was an openness that existed in the world of computing. Despite all that was said of Microsoft back then, and much of the complaints about proprietary software were true then…

That early era also included some controversy over Windows XP requiring online activation. It was a watershed moment, soon followed by their authenticity check to install certain updates.

We are firmly in a new era of increasing DRM within the OS. As a producer I can see the desire but am saddened as a consumer with fond memories of a freer time.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#295
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

Call me paranoid, but I am completely certain that TPM has a backdoor disguised as a very sophisticated bug for plausible deniability.

I'll never trust BitLocker or anything that relies on TPM to encrypt any data I actually care about not being compromised (read: my very personal data, not work data).

Re: Microsoft no longer signs Windows drivers for Process Hacker

#296

Earlier quoted context omitted.

> Imagine tax software (comercial or gov provided) refusing to work unless you use an OS with TPM support for "security reasons". > I don't think this will happen any time soon (hopefully) but I can see how even making your own hardware might no be enough. This already happened in Android, at least where I lives (Indonesia). Most of Banks, Government Services, and freaking McDonald's apps will refuse to run if your p…

Honest question: how do those apps know your phone is rooted, and can you still use their websites for equivalent functionality?

Google provides attestation and it's a constant cat-and-mouse game that the rooters are usually losing.

Websites can't tell, but lots of companies don't provide equivalent functionality via website. I know I can't upload check images for remote deposit unless I use the native banking app.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#297

Earlier quoted context omitted.

>And in fact Secure Boot does protect against Grandma being infected by boot-time malware. And how can grandma get boot time malware at Home? IIRC those were common back in the days when people were plugging in infected floppy disks or thumb drives everywhere and you'd try to boot off them. Can't remember last time I saw this type of malware in the wild as phishing and ransomware is a lot more profitable for maliciou…

> This was always the case ever since secure boot launched and any OS that didn't have it's first stage bootloader signed by Microsoft could not boot. Even To this day, to install arch or puppy on my XPS i had to disable secure boot. Ubuntu and other major distros are fine here though but this gate keeping doesn't make it ok in my book. But this is kind of a circular problem, isn't it? If everyone's bootloader is sig…

>to me what's important, as another sibling says, is that the user be able to load their custom keys with which they sign their own bootloader. This is how I run Arch on my HP computers.

Like I said above, this and stuff like management engine and TPM makes perfect sense in the enterprise environment where the owner of the device (the employer) is different than the user (the employee), so IT needs to strictly control what's running on the devices they trust on their infrastructure, but why should we expect home users to have to sign bootloders to use whatever software they want as they're both the users and the owners of the devices and the network infrastructure in their homes?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#298
post #269

Earlier quoted context omitted.

Are you aware of the enormous amounts of blood, sweat, and tears expended by people on XDA Developers just to unlock bootloader to use functions as simple as custom gesture controls?

Are you aware of how often they fail?

Exactly. It's very much a war about what programs users can run, and the users don't always win.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#299

Earlier quoted context omitted.

To give an example harm caused by the TPM / disk encryption feature in the consumer space: A recently-deceased friend's wife contacted me about getting personal data off from her late husband's computers. I ended up being able to get nothing for her. My friend, no doubt influenced by dementia and paranoia he was feeling, changed the passwords, made no note of them, and subsequently died. The computers in question run…

This is similar to why enabling 2FA actually scared the heck out of me! I use a password manager to generate strong unique passwords, so I think the chances of someone getting in that way are incredibly low. But I can absolutely see myself loosing all of my 2FA keys some day in a freak accident.

You are supposed to store the recovery key(s) in a secure location. Then if you lose your 2FA device, you can reset your 2FA from those recovery keys.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#300

Earlier quoted context omitted.

I genuinely miss the days of playing with DOS, Windows 9x and then all the excitement of Windows XP. All on my own hardware, which was whatever I could scrape from parents, savings, neighbours. I could do what I wanted with these old PCs. There was an openness that existed in the world of computing. Despite all that was said of Microsoft back then, and much of the complaints about proprietary software were true then…

I have a theory that this seismic shift is the result a demographic shift of PC users. It gradually went from engineers, businessmen and hackers to a much wider audience including younger people who have trouble grasping concepts such as folders[0] This by itself is not bad, problems arise when companies use this to justify deny control even from those who can be responsible with it. [0]: https://www.pcgamer.com/stud…

The problem arises when there is no way to differentiate between the user classes. And while I enjoy computing freedom, I’m not exactly proclaiming its value when I have to deal with a DDoS or hear about people getting ransomwared. I know things like Mirai also exist, and that user error isn’t the only ransomware vector, but poor computing habits absolutely fuel such problems and they cause pain for society as a whole.

I have no idea what the answer is, other than having Linux et al be the place for free computing (protected by its various barriers to entry) while the consumer OS space eventually becomes increasingly locked down. The only other ideas I have are dumb ones like requiring regular examination/certification/licensure to be able to use the “developer” version of Windows or something.

Post reply on HN