Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

351–360 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#351

Earlier quoted context omitted.

What did you expect? Microsoft labeling their data collection actions as "spyware" themselves? "Spyware" is a term used by people who oppose data collection, they didn't ask for. "Telemetry" is an euphemism by the ones that build this data collection into their apps.

I expect professionals to be able to distinguish between the two instead of being suckered into some sort of hive-mind thinking of "all data gathering bad hurr durr". I'm absolutely all for privacy and limiting unnecessary gathering of data. But there's nuances to this discussion and labeling everything that has any amount of telemetry as "Spyware" does not do anyone any good.

> some sort of hive-mind thinking of "all data gathering bad hurr durr"

Maybe it's not "hurr durr" and people have a legitimate reason to hold that opinion. To those people, any distinction between spyware and "good" telemetry is merely academic and effectively irrelevant.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#352
post #23

The article mentions Process Explorer. Since Sysinternals were bought by Microsoft many years ago and the tools are distributed directly via Microsoft, such tools are unlikely to have an issue being signed. A brief history of the process for those not following it. Originally for kernel-mode drivers, you needed a code signing certificate cross signed by Microsoft's root . This means that the certificate follows a cha…

qBittorrent developers just said fuck it three years ago, and let the world burn with unsigned installer. I suggest everyone to join the civil disobedience. If you don't, you'll soon find out you can't run your programs.

User mode code is a different scenario. There are three possibilities:

- unsigned code pops up with a big warning 'your pc will explode' or something like that when you try to run it. - signed code does not need a cross signed certificate. Any CA can include the code signing oids and voila. This displays as yellow but the CN is extracted as the publisher name. - Finally EV certificates give you 'instant reputation' i.e. no orange warning. The difference is entirely audit related and the OIDs you may include. The crypto is identical to normal certs.

This I'm fine with. I understand Microsoft wanting to protect their kernel and the user experience and I'm on board with that but I like the fact that windows has traditionally been a very open system. It is a real shame it is heading the other way.

I haven't developed windows drivers for years though, or used windows as my daily machine for years either (it was Linux at home, windows at work, now Linux for both).

Re: Microsoft no longer signs Windows drivers for Process Hacker

#353
post #29

Because of things like this, I'm at the point where I consider the invention of public-key encryption to be the worst thing that's ever happened to the world. If governments had _immediately_ preemptively classified anything related to assymetric encryption—and actively enforced the classified status—as soon as the first research into it started appearing, the world would be a much better place than it is now.

DSA and RSA are pretty straightforward math. ECDSA is somewhat more complex but still pretty basic.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#354

Earlier quoted context omitted.

It can be installed without a TPM chip. My computer does not have a TPM and they say it will soon be eligible for Windows 11. If you can't wait, you can do a full install using an ISO image.

You can't install W11, not even from ISO, if your computer doesn't meet all the requirements (yes, I tried).

There are some remastered ISOs floating around.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#355

Earlier quoted context omitted.

It's called SafetyNet [1] What irked me is sometime app developers are abusing it without asking themself "Does this app really need to check for rooted phones at all?" I'm okay if banks apps are using that. But why does fast foods apps need to use that? Most people that I know are paying with cash when they order foods online (and you can't hack paper money with rooted android phones). [1] https://developer.android.…

Platforms like deliveroo have lost tens of millions to fraud, I don’t blame them for enforcing safetynet. Perhaps “food delivery” means pizza to you, but there are many places where it also includes thousand dollar bottles of wine.

Could you explain how the locked-down phone is protection against fraud here?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#356

Earlier quoted context omitted.

Isn't that just because the default library is in the steam install folder? (On windows)

Yeah, and Valve can’t be arsed to change it.

Because that won't make them any money like their loot boxes.

As for the matter, some teams here are just as incompetent so someone's probably going to have a fire lit under their arse to either fix the signing issue or publicly document why these APIs are now "protected"

Re: Microsoft no longer signs Windows drivers for Process Hacker

#357
post #55
post #37

Earlier quoted context omitted.

Very informative. And presumably on OSX none of this applies because it's all BSD underneath? Or is OSX different again to just running BSD out of the box?

On macOS, you have those options: - SIP off (totally, or just driver signature enforcement) - kernel driver (deprecated, Apple doesn’t issue new certs anymore it seems) - system extension (user-mode driver, explicitly intended for device compatibility)

[deleted]

Re: Microsoft no longer signs Windows drivers for Process Hacker

#358

Earlier quoted context omitted.

Not long ago I upgraded an Ubuntu system to 21.04. It took me more than half an hour of looking around to realise that the "Ubuntu Software" screen everyone was referring to was a separate application that wasn't installed by default . Then I could look up the CLI command to install it via apt. That sort of thing would be a small (though very irritating) waste of time for many of us on HN but it could have been a sho…

The "Ubuntu Software" screen should be installed by default. > Ubuntu Software Center is a one-stop shop for installing and removing software on your computer. > It is included in Ubuntu 9.10 and later. > - https://help.ubuntu.com/community/UbuntuSoftwareCenter

The "Ubuntu Software" screen should be installed by default.

"Should" being the operative word unfortunately. It clearly wasn't installed by default for this machine that had been upgraded through earlier versions (starting around 16 I think so well after 9.10), nor was there any obvious indication to the user that it was missing and available to be added.

There were some other oddities after that upgrade, for example Firefox no longer appearing for one-click launching from the default UI layout when it had before, so the lack of Ubuntu Software (and, apparently, its underlying apt package) wasn't the only anomaly. It just wasn't a polished experience that a non-technical user should have to deal with.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#359

Earlier quoted context omitted.

I saw the writing on the wall the moment they could sloppily justify the TPM requirement. Then I got into arguments with people proclaiming that it's just Microsoft enforcing it for the casual user's safety, and that I'm a Microsoft hater. Who? Me, whose first programming language was C#, who worked as an Windows server administrator for years, and my operating systems have been nothing than Windows for 2 decades. An…

I genuinely miss the days of playing with DOS, Windows 9x and then all the excitement of Windows XP. All on my own hardware, which was whatever I could scrape from parents, savings, neighbours. I could do what I wanted with these old PCs. There was an openness that existed in the world of computing. Despite all that was said of Microsoft back then, and much of the complaints about proprietary software were true then…

I completely agree with your points.

> I don't feel the same way towards my garden hose or washing machine.

We just built and furnished a remote vacation home from the ground up and the shiny new appliances and even some fixtures (mostly ordered or approved by my wife) default to stubbornly demanding cloud access, often before they will even perform their most basic functions. At the moment, internet is only via 4G hotspot as we await Starlink's rollout next year.

This of course includes the Samsung TV but extends to the Denon amplifier, all the major appliances from washing machine, refrigerator etc all the way down to the light switches, thermostats and 'smart' toilets (which I view as 'input-only' devices). Fortunately, I intercepted the light switches before installation and hacked open source firmware on them but that required opening each one and temporarily soldering to reflash the firmware (I had to draw the line somewhere).

Most of the devices can be coaxed into functioning without permanent cloud access but it's a time-consuming escape-room adventure through dark UX patterns. The rest will require blocking at the router firewall level.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#360
post #332

Earlier quoted context omitted.

Not long ago I upgraded an Ubuntu system to 21.04. It took me more than half an hour of looking around to realise that the "Ubuntu Software" screen everyone was referring to was a separate application that wasn't installed by default . Then I could look up the CLI command to install it via apt. That sort of thing would be a small (though very irritating) waste of time for many of us on HN but it could have been a sho…

Is synaptic not a thing anymore? I haven't used linux in a number of years.

Synaptic still works fine but it also needs explicitly installing and it is aimed at more technical "power users" and so solves a slightly different problem.
Post reply on HN