Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

401–410 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#401
post #382

Earlier quoted context omitted.

Exactly right. The move to ARM will highlight the hardware freedom in a big way. People are used to ARM being different and are that much more likely to forget open, general purpose computing right along with that "old" x86... Heh, I always disliked x86. But now? I look at it fondly. Strange times. Edit: It is the IBM PC lineage I speak of here, not just the ISA.

It's not the instruction set - it's the IBM PC-compatible standard that gave us our golden era of desktop computing. Standard bootloaders, standard ports, standard keyboard layouts. We owe it so much.

Yes, I agree and just made the reference off hand.

We do!

[Looks over at Apple //e and IBM XT]

We need another open effort. Soon.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#402
post #3

Is there no way to run unsigned software on windows?

For drivers, I don’t think so. You can enable some boot settings that allow you to run unsigned drivers, for development purposes, but it will revert upon reboot, without anyway to enable it permanently.

The last I checked there's a patch that will make it permanent, but of course the patcher itself is labeled as "malware" by plenty of AVs, possibly even Windows Defender itself.

Also, updates will probably revert the changes too.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#403

Earlier quoted context omitted.

I'm not familiar with the rest but how is Always-on-top locked away? Its such a basic thing and a lot of programs are using it.

SetWindowPos with HWND_TOPMOST fails with Access Denied. CreateWindowInBand also fails with Access Denied.

That's so weird. No idea why they restricted that but not the other ways of setting a window to always stay on top. Like whatever Firefox's picture-in-picutre uses.

EDIT: I guess they want to prevent you from doing interesting things like staying on top of the lockscreen. This article sheds some light on the Z ordering changes since win8 https://blog.adeltax.com/window-z-order-in-windows-10/

Re: Microsoft no longer signs Windows drivers for Process Hacker

#404
post #53

Earlier quoted context omitted.

"Dan would eventually find out about the free kernels, even entire free operating systems, that had existed around the turn of the century. But not only were they illegal, like debuggers—you could not install one if you had one, without knowing your computer's root password. And neither the FBI nor Microsoft Support would tell you that." --Richard Stallman, "The Right To Read"

In a future where laws mandate signed software, the only way out is to somehow make our own hardware. We'll never be truly free unless we can manufacture free computers at home just like we can write free software at home. There is no software freedom if the processor refuses to run our code. Right now the chip fabs require billions of dollars in investments in order to make our processors. They are single points of…

In a future where laws mandate signed software

"If you outlaw freedom, only outlaws will have freedom."

Re: Microsoft no longer signs Windows drivers for Process Hacker

#405
post #58
post #8

Earlier quoted context omitted.

Where did they actually do nice things? VSCode is still not entirely open source and the official builds have spyware included.

It's honestly weird to see "Telemetry" labeled as "Spyware" by a technical people that, quite frankly, should know better. Spyware is NOT the same as gathering Telemetry data. You can also just turn off Telemetry in VSCode in the settings. I think a vast majority of people on HN gather data on customer usage of the products that they build. Because it ultimately makes us able to tailor the products better for our cus…

My issue with telemetry is it increases the chances of data leakage. I don't care if Microsoft gets data on what commands I'm selecting from the menus. What I do care about is that they record any free-form entries. Let's say they want to know everything I type in the command palette so they can figure out if they should add aliases for certain actions. That doesn't sound too bad until you consider the case where you tried to paste in what you were looking for, but forgot that you had something very personal in the clipboard. Once that happens, you just have to hope that the first person to see it is a good enough person to wipe all traces of that info out.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#406

Earlier quoted context omitted.

I have a theory that this seismic shift is the result a demographic shift of PC users. It gradually went from engineers, businessmen and hackers to a much wider audience including younger people who have trouble grasping concepts such as folders[0] This by itself is not bad, problems arise when companies use this to justify deny control even from those who can be responsible with it. [0]: https://www.pcgamer.com/stud…

The problem arises when there is no way to differentiate between the user classes. And while I enjoy computing freedom, I’m not exactly proclaiming its value when I have to deal with a DDoS or hear about people getting ransomwared. I know things like Mirai also exist, and that user error isn’t the only ransomware vector, but poor computing habits absolutely fuel such problems and they cause pain for society as a whol…

Let's pretend there is no financial interest in restricting computer access. I think the best and safest option would be to manufacture all PCs with a similar mechanism to chromebooks write protect screw that you have to remove to unlock the bootloader. But instead of just unlocking the bootloader it also gives you TrustedInstaller privilege in windows.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#407

Earlier quoted context omitted.

Arguably this is Valve's fault because they insist on putting a ton of stuff in secure folders (under Program Files) instead of where they belong (in the user's home/data directories) They've had a LONG time to fix this.

Isn't that just because the default library is in the steam install folder? (On windows)

They don't just put the games there, they put the steam cloud data there too, and I think screenshots etc.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#408

Earlier quoted context omitted.

Arguably this is Valve's fault because they insist on putting a ton of stuff in secure folders (under Program Files) instead of where they belong (in the user's home/data directories) They've had a LONG time to fix this.

That's just game fault that it saves data in game files instead of user directory.

No, Steam puts stuff like steam cloud in the programfiles dir as well. It's totally under their control where it goes.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#409
post #127

Earlier quoted context omitted.

>purely arbitrary As if years of experience hasn't taught us that opt-in security is stupid. This would be arbitrary if the TPM was useless, but it isn't.

We have to disagree here. The threat models where the security that TPM offers are mostly applicable to the enterprise and business sectors where all devices on the network/AD/VPN have to be trusted and their storage encrypted. There TPM makes perfect sense. You average consumer/home user does not benefit at all from the features of TPM since they're not subject to the same threat model. Here TPM, and also stuff of t…

This assumes that home users don't have any data worth protecting. I think that's a ridiculous thing to assume.

IME does not affect your average user at all, so I'm not sure why you'd bring that up.

>remember how enabling secure boot originally meant you couldn't install any linux distro?

A lot of people were spreading this FUD back when secure boot was being introduced. It was a lie back then, it is a lie now.

> rather than add any meaningful security (will TPM and Secure Boot prevent grandma from getting her PC infected by malware off some shady phishing site? No? Then don't force those requirements for private users)

Secure Boot essentially killed off bootkits, that's a significant achievement. Perhaps you should learn what these technologies are actually used for before attacking them?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#410

Earlier quoted context omitted.

What did you expect? Microsoft labeling their data collection actions as "spyware" themselves? "Spyware" is a term used by people who oppose data collection, they didn't ask for. "Telemetry" is an euphemism by the ones that build this data collection into their apps.

I expect professionals to be able to distinguish between the two instead of being suckered into some sort of hive-mind thinking of "all data gathering bad hurr durr". I'm absolutely all for privacy and limiting unnecessary gathering of data. But there's nuances to this discussion and labeling everything that has any amount of telemetry as "Spyware" does not do anyone any good.

Collecting data to "improve" programs and then not doing any improvement really look like spyware.
Post reply on HN