Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

301–310 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#301

Earlier quoted context omitted.

In a future where laws mandate signed software, the only way out is to somehow make our own hardware. We'll never be truly free unless we can manufacture free computers at home just like we can write free software at home. There is no software freedom if the processor refuses to run our code. Right now the chip fabs require billions of dollars in investments in order to make our processors. They are single points of…

But even if you can somehow make your own hardware, how long until governments start requiring interaction with certain services (health, banking, taxes, etc) be signed by an _approved_ OS/processor combo? Imagine tax software (comercial or gov provided) refusing to work unless you use an OS with TPM support for "security reasons". Or even worse, what would happen if gov regulations started requiring ISPs to stop wor…

AT&T fiber basically alreadydoes this. You cannot connect without their crappy routerbox that authenticates to the network every so often. Some people have created work arounds but they all requie the att box be plugged in somewhereand forward its certificates

Re: Microsoft no longer signs Windows drivers for Process Hacker

#302
post #214

Earlier quoted context omitted.

What about the scenario where your laptop is stolen and the attacker reads your data off the disk? All modern mobile devices protect against this scenario by default, but Windows devices required additional configuration to be protected. And in fact Secure Boot does protect against Grandma being infected by boot-time malware. And when has it ever been the case that it prevented you from installing Linux?

>And in fact Secure Boot does protect against Grandma being infected by boot-time malware. And how can grandma get boot time malware at Home? IIRC those were common back in the days when people were plugging in infected floppy disks or thumb drives everywhere and you'd try to boot off them. Can't remember last time I saw this type of malware in the wild as phishing and ransomware is a lot more profitable for maliciou…

> And how can grandma get boot time malware at Home?

Depending on the demographic, they can: get caught up in during some (possibly unrelated, likely automated) attack, click the wrong ad, or load the wrong common page with JS.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#303

Earlier quoted context omitted.

I had to disable secure boot to get Nvidia's drivers to work. So I guess the end result might be more hardware trouble for distros, with a subsystem that tries to prevent usage of the computer when it is not happy.

You can also enroll your MOK (Machine-Owner-Key) to UEFI and then sign the nvidia driver with it. That way, you can leave Secure Boot enabled. However, leaving the secret part of MOK on the machine and let the dkms or whatever updater of kernel modules to use it unattended kind of defeats the purpose.

Is the NVIDIA driver already signed? If it is, couldn't you create a certificate signed with the root key that says that the NVIDIA key is trusted?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#304

Earlier quoted context omitted.

> Apple assumed market dominance and locked everything down on mobile. Apple has about 26% market share on mobile globally, that's not exactly market dominance. Them locking down the platform limits piracy, which is one reason why developing for iOS is much more profitable for many kinds of apps, which causes better apps that drive consumers to the iPhone. That's the reason they put so much energy into locking down t…

Locking things down and snooping are always presented as an advantage. Stoping piracy, stoping CP, stoping drug dealers and so on. Maybe we should have some company lock us in our houses for safety? You know, if you wander outside you might get robbed.

Explaining the economic reasons why things are done is always seen as an endorsement of them. I don't think that's justified.

I don't like how Apple locks down their phones, that's why I prefer Android. That doesn't mean I can't appreciate why they do it and why some people might prefer it.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#305

Earlier quoted context omitted.

an who of an average user does need that? I'm not an average user but I never need that. I also know no one who can't wait to get it or even think about wanting it. I only read in blogs or HN that one would need it. I think "you need that because of security" is PR/propaganda from certain companies.

As someone with executive function and memory issues, being able to use short pins/passwords to access my secured hardware is incredibly useful.

What threat model do you have that has people breaking I using a short password?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#306
post #227

Earlier quoted context omitted.

I'm not the person you were replying to, but here's the straw that broke this multilingual camel's back: unless Gnome is running under Wayland, switching the keyboard layout steals the input focus away from the foreground window briefly, causing focus-loss event handlers to fire. This might seem an easily fixable minor issue but it's actually a decade-old hairball which significantly harms the experience and can't be…

Isn't Wayland standard in 21.04? So it's already fixed? Ed: > it's actually a decade-old hairball which significantly harms the experience and can't be fixed cleanly under X. This is literally the whole argument for Wayland - things that can't be fixed under x11?

I didn't notice Wayland becoming the default, tbh. Thanks for mentioning this. As for the specific bug, it was introduced by the implementation of a non-essential feature (the languague switch HUD) which was then left in place, likely because the Wayland transition was juuust around the corner. While Wayland does address many architectural issues, I don't think X users should deal with regressions caused by Wayland-optimized features just yet (and definitely not 8 or so years ago).

Re: Microsoft no longer signs Windows drivers for Process Hacker

#307
post #92

Earlier quoted context omitted.

Or maybe this is related to the security, and Windows is the only widely used platform that didn't enforce TPM until recently? macOS is even more locked down, but they don't impede or force users to use Mac App Store.

Ofcourse they don’t force anything because of the competing windows platform which is more open up to now. Apple assumed market dominance and locked everything down on mobile. What I infer from your observation is that closing down Windows could also adversely affect Mac users, since Apple would not miss this opportunity.

So if one OS company moves in a certain direction, the other one can do so safely. Implicit collusion.

Apps need to run/execute in an open source runtime environment that operating systems can choose to integrate...and would need to if they wanted to run any of the applications on the market. The browser is not the answer.

Once these guys get settled in they are going to push for regulation that will somehow preclude people from using Linux desktops.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#308

Earlier quoted context omitted.

This is similar to why enabling 2FA actually scared the heck out of me! I use a password manager to generate strong unique passwords, so I think the chances of someone getting in that way are incredibly low. But I can absolutely see myself loosing all of my 2FA keys some day in a freak accident.

You are supposed to store the recovery key(s) in a secure location. Then if you lose your 2FA device, you can reset your 2FA from those recovery keys.

What secure location? My sock drawer? Or am I expected to go buy a safety deposit box? I'm really not that organized and I loose slips of paper all the time, it's a major reason I was drawn to computers growing up.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#309
post #289

Earlier quoted context omitted.

The issue isn't the TPM, it's who owns the keys to the machine. If the user configures their own keys, it becomes an empowering technology that allows them to verify their boot process hasn't been tampered with. If Microsoft owns the keys, they own the computer and the technology becomes their means of control over the user. They will use this technology to oppressively deny the user their software freedom while simu…

Insightful analysis, though "oppressively deny" sounds harsh to me. There is not a blatant malice in TCG per se, mainly a neutral desire for control and by proxy profit. The treacherous versus trusted computing debate really does boil down to control. Do we trust vendors to be stewards of control on our platforms? Do we even have a choice? I do not recall giving the keys to anyone, and yet it feels like the person bu…

> A similar issue exists with cell phone debug, where the carriers log into your phone to troubleshoot.

You cannot be serious. How do I know if this can happen to me?

> Free open source hardware (FOSH) is really the only option.

Yes.

> No user complains too much about not being able to replace the firmware for some faraway BGP router

The network is a very clear line to me. The BGP router is not my computer. It's the ISP who should be demanding free software from their hardware manufacturers, so that they too could enjoy complete control and trust.

> If a consumer thinks about the PC less as providing a personal computing service and more as an Internet terminal, then the problem goes away a little.

In these cases, the user is not using a computer. They're using appliances that just happen to have computers inside. Modern consumer products make every effort to hide the computer. There is no computing freedom if there are no computers we can use.

We must oppose all "consumer" products, all "fully integrated and converged" solutions. Computing is about simple parts in the form of hardware and software; from these parts, powerful systems emerge. Consumer appliances are these whole things that have swallowed up the entire system. They are indivisible, non-interoperable, uncontrollable, they only do what was foreseen by the corporation that made them despite the perfectly capable computer inside. I can't interface directly with the computer controlling my air conditioner, I need an infrared controller for that.

This article is linked from Stallman's website, it covers this matter with a lot of depth:

http://contemporary-home-computing.org/RUE/

> We are giving up our last rights and freedoms for “experiences,” for the questionable comfort of “natural interaction.”

> But there is no natural interaction, and there are no invisible computers, there only hidden ones. Until the moment when, like in the episode with The Guardian, the guts of the personal computer are exposed.

> Every victory of experience design: a new product “telling the story,” or an interface meeting the “exact needs of the customer, without fuss or bother” widens the gap in between a person and a personal computer.

> The morning after “experience design:” interface-less, desposible hardware, personal hard disc shredders, primitive customization via mechanical means, rewiring, reassembling, making holes into hard disks, in order to to delete, to logout, to “view offline.”

Re: Microsoft no longer signs Windows drivers for Process Hacker

#310

Earlier quoted context omitted.

> This was always the case ever since secure boot launched and any OS that didn't have it's first stage bootloader signed by Microsoft could not boot. Even To this day, to install arch or puppy on my XPS i had to disable secure boot. Ubuntu and other major distros are fine here though but this gate keeping doesn't make it ok in my book. But this is kind of a circular problem, isn't it? If everyone's bootloader is sig…

>to me what's important, as another sibling says, is that the user be able to load their custom keys with which they sign their own bootloader. This is how I run Arch on my HP computers. Like I said above, this and stuff like management engine and TPM makes perfect sense in the enterprise environment where the owner of the device (the employer) is different than the user (the employee), so IT needs to strictly contro…

I agree that the process could be more straight-forward, especially as, from what I read, some computers may need some coaxing into changing the keys.

But the thing is that, like it or not, most people simply don't care enough, so they'll just use Windows. I remember a while ago, when there were many live CD-based distros and there was no such thing as SecureBoot, people wouldn't even be curious to give Linux a spin. All it would have taken was to pop a CD in the drive and boot up. To paraphrase another commenter, I think many people feel the same way about their PC as their washing machine: just another appliance. Of course, lock-down platforms don't help instill curiosity in people...

So you get, roughly-speaking, two populations: those who care and those who don't. And usually, those who do care are curious enough to follow a few simple steps to disable SecureBoot for the installation and then set up their own signing process.

But I stand by what I said earlier: the process cannot be fully automatic, or it defeats the purpose. But I do think that willingly making it a pain is wrong.

Post reply on HN