Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

421–430 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#421

Earlier quoted context omitted.

It brings enormous security benefits to end users. TPMs drastically reduce entropy/complexity requirements for things like passwords/pins since the TPM can rate limit guess attempts. Doing that without a TPM is impossible since an attacker can always read the encrypted password off of the drive/directly from memory and then brute force it.

HDD content can be encripted without storing the password anywhere, without a TPM. If the ecryption algorithm is decent, good luck waiting billions of years to bruteforce, even with the next gen hardware.

What secret do you use to encrypt the hard drive? That itself ends up being a password/key file that needs to get stored somewhere whether it is someone's brain or a more secure storage location. I guarantee you that whatever password average users pick will not take billions of years to brute force, more like an hour tops.

I don't think it should have been required for Windows 11, but TPMs are a useful tool for mitigating brute force attacks.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#422
post #58
post #8

Earlier quoted context omitted.

Where did they actually do nice things? VSCode is still not entirely open source and the official builds have spyware included.

It's honestly weird to see "Telemetry" labeled as "Spyware" by a technical people that, quite frankly, should know better. Spyware is NOT the same as gathering Telemetry data. You can also just turn off Telemetry in VSCode in the settings. I think a vast majority of people on HN gather data on customer usage of the products that they build. Because it ultimately makes us able to tailor the products better for our cus…

> You can also just turn off Telemetry in VSCode in the settings.

Such a feature should be disabled by default.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#423
post #371

An immensly powerful and useful tool. Can't live without it. Hopefully the situation resolves soon. What is it with MS these past few months? It's like they're trying to throw away the little community goodwill they managed to build up over the years.

Shareholders are getting anxious.

I don't think so.

https://ycharts.com/companies/MSFT/price

Re: Microsoft no longer signs Windows drivers for Process Hacker

#424
post #336
post #54

Earlier quoted context omitted.

Ironically I have been using Linux via VMWare for about 10 years now, because I got fed up with Year of Linux Desktop, which to this day still doesn't provide a proper experience to anyone that cares about graphics programming and usable UI/UX tooling. When my Asus Netbook dies (1215B with XUbuntu), the next UNIX travel laptop will be an Air. So you can spare the talk about how much GNU/Linux has progressed, since I…

VMWare vs Native Linux running last Gnome is a very, very different experience in my laptop. VMWare is crippled performance wise, doesn't detect autorotate, and using it in full-screen requires me to resize the VMWare window every time I reboot the VM. VMWare also doesn't detect all the buttons in my mouse.

My first Linux distribution was Slackware 2.0 bought in 1995's Summer, and have used VMware since 2010, so all anecdotes.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#425

Earlier quoted context omitted.

It's one command and you're forever in test mode[1], i.e.: don't enforce driver signatures: bcdedit /set testsigning on You just have to disable Secure Boot in UEFI first. (And I can confirm Windows 11 doesn't actually require Secure Boot to boot, I've had it off for months as part of win11 certification testing.) I'm not sure but DRM might revert to lower levels (e.g.: 720p), but that also happens on macOS when you…

One thing to note is that game anti cheats will just lock you out if you are in this mode. It’s the reason that game cheat makers look for exploits in random drivers to load their cheat in kernel space.

https://github.com/Mattiwatti/EfiGuard

Re: Microsoft no longer signs Windows drivers for Process Hacker

#426
post #272

Earlier quoted context omitted.

Microsoft released their own Linux: https://www.tomshardware.com/news/microsoft-released-cbl-mar... As far as opensource DOS, nothing beats FreeDOS: https://www.freedos.org/

>>CBL-Mariner is an internal Linux distribution for Microsoft’s cloud infrastructure and edge products and services. Oh yes please...i want that universal Linux Distribution ;) >nothing beats FreeDOS Dosbox and dosbox-x beat FreeDOS anyday.

Call me when you can run real drivers in DOSBox-X.

And, still, XDOSemu+FreeDOS runs circles over DOSBox and DOSBox-x.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#427
post #225
post #54

Earlier quoted context omitted.

Ironically I have been using Linux via VMWare for about 10 years now, because I got fed up with Year of Linux Desktop, which to this day still doesn't provide a proper experience to anyone that cares about graphics programming and usable UI/UX tooling. When my Asus Netbook dies (1215B with XUbuntu), the next UNIX travel laptop will be an Air. So you can spare the talk about how much GNU/Linux has progressed, since I…

> a proper experience to anyone that cares about graphics programming and usable UI/UX tooling. I suppose the only answers here are qt or game engines like godot/heaps.io etc - and they probably aren't as good as windows. But it's a little tricky to know exactly what you mean. > When my Asus Netbook dies (1215B with XUbuntu), the next UNIX travel laptop will be an Air. > So you can spare the talk about how much GNU/L…

Qt isn't a OS framework like Cocoa, or WPF/Win32.

It is the best cross-platform C++ GUI framework, but nothing specific to Linux per se.

Thanks for educating me on Linux distributions, pity that I have been using them since 1995, and yes it is the LTS version, it tends to break less.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#428
post #55
post #37

Earlier quoted context omitted.

Very informative. And presumably on OSX none of this applies because it's all BSD underneath? Or is OSX different again to just running BSD out of the box?

On macOS, you have those options: - SIP off (totally, or just driver signature enforcement) - kernel driver (deprecated, Apple doesn’t issue new certs anymore it seems) - system extension (user-mode driver, explicitly intended for device compatibility)

> Apple doesn’t issue new certs anymore it seems

This is not true. kexts are still signed by apple after being submitted and vetted.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#429
post #94

Earlier quoted context omitted.

> Spyware is NOT the same as gathering Telemetry data. Telemetry and spyware differ only in the way collected data is used.

I would say the intent very much dictates the what and how of Telemetry as well. There's a huge difference between gathering data on feature usage of VSC vs e.g. slurping up the code from its users. A lot of software lets you opt-out from Telemetry gathering when you install it. I would not think Spyware would do this. And I feel like saying it's " only in the way collected data is used" really makes a small thing ou…

Actually there are of course different levels of bad like in any other area of human endeavor. Many criminals who would happily break your car window to steal your laptop wouldn't kill you to sell your Kidneys.

Lots of spyware that wants to remain on one side of a less dramatic divide simply provides "options" for example in the installer that are opt in and vaguely defined that no sane individual fully understanding his options would opt for.

Such software isn't usually cryptolocking your family pictures instead its frequently grossly violating your privacy and selling your time and attention to third parties who in turn may opt to use this bought and paid for back door into your computer to waste your time or cryptolock your family pictures.

Here's a clue. If you have to make a feature opt out because nobody on earth would opt in given time and expertise sufficient to understand your offer then you are victimizing your user. I cannot think of a case where any data collection being anything other than opt in would be acceptable.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#430

Earlier quoted context omitted.

This is similar to why enabling 2FA actually scared the heck out of me! I use a password manager to generate strong unique passwords, so I think the chances of someone getting in that way are incredibly low. But I can absolutely see myself loosing all of my 2FA keys some day in a freak accident.

Nowadays the password managers can store the 2fa secrets and generate the codes as needed. It kind of defeats the purpose of the second factor -- the password manager becomes it -- but at least it makes the services that insist on it happy.

Nowadays 2FA are always about something you know and somebody that vouches for you (SMS, email, whatever). Nobody seems to do any version of it that relies on you alone. So a password manager won't improve its reliability.
Post reply on HN