Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

431–440 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#431

Earlier quoted context omitted.

Platforms like deliveroo have lost tens of millions to fraud, I don’t blame them for enforcing safetynet. Perhaps “food delivery” means pizza to you, but there are many places where it also includes thousand dollar bottles of wine.

Could you explain how the locked-down phone is protection against fraud here?

Statistically people who do payment fraud crap use rooted phones more, probably to help with things like location spoofing to get around other fraud detection methods when apps use third party payment libraries, so you reduce your fraud cost with something that is a few lines of code. The cost/benefit ratio is too good which is why you see it everywhere that has a payment fraud risk of some sort.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#432

Are there TPMs where the user has more control and can configure w/ a root password to control keys? I like the idea of a secure tamper resistant security device but I don't like that the owner of the PC does not retain absolute control over this device.

> the owner of the PC does not retain absolute control over this device.

This is a bit FUD-y. TPMs are key stores, the same as what Apple calls a "secure enclave." When you activate a device with a service like Netflix or a software like Windows, they stick their key in the TPM. As a user you can clear of disconnect the TPM any time you like - you're in control of your device. What you're not in control of is Netflix and Windows - Netflix and Windows are only going to authorize 5 TPMs. If you reset your TPM, you're going to need to re-enter your license information.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#433

Earlier quoted context omitted.

But even if you can somehow make your own hardware, how long until governments start requiring interaction with certain services (health, banking, taxes, etc) be signed by an _approved_ OS/processor combo? Imagine tax software (comercial or gov provided) refusing to work unless you use an OS with TPM support for "security reasons". Or even worse, what would happen if gov regulations started requiring ISPs to stop wor…

That would be oppressive but at least the unfree activities are restricted to the parts of our life where we must deal with authorities. We are still free to do whatever we want with our free computers in all other cases. > Or even worse, what would happen if gov regulations started requiring ISPs to stop working with non-compliant hardware? I.e. something like requiring network devices to attest they are "oficially"…

Ad-hoc radio mesh networks are constrained by physics and math as far as throughput goes, they are not competitive with normal networks. Governments have also shown the ability to regulate radio usage very well the world over.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#434
post #426
post #272

Earlier quoted context omitted.

>>CBL-Mariner is an internal Linux distribution for Microsoft’s cloud infrastructure and edge products and services. Oh yes please...i want that universal Linux Distribution ;) >nothing beats FreeDOS Dosbox and dosbox-x beat FreeDOS anyday.

Call me when you can run real drivers in DOSBox-X. And, still, XDOSemu+FreeDOS runs circles over DOSBox and DOSBox-x.

> Call me when you can run real drivers in DOSBox-X.

That's exactly what i don't want.

>And, still, XDOSemu+FreeDOS runs circles over DOSBox and DOSBox-x.

No, not really have you even installed FreeDOS once? BTW the FreeDOS developers will perfectly tell you that they have no interest in being dos game focused...and you can feel that 50% of all games just refuse to run...that's not the case with MSDOS 5.22.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#435

Monopoly abuse by any other name is still just that. Microsoft never did change, nor will it, no mater how many they manage to fool, manipulate or bribe. It remains a criminal enterprise that should be cut down. But that will never happen, as long as the government(s) controlling this company are made of the same DNA. Good luck to those who have the luxury of a choice to avoid this company (and similar ones). Even mo…

Microsoft shouldn't rely on this too much honestly. They still have mass, money and maybe an edge but the rest of the world changed, and is potentially ready to pick up the pieces if need be. I thought recent efforts of MS were a sign of wisdom somehow.

...and maybe an Edge?

No, they sold out to Google on that already.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#436
post #55

Earlier quoted context omitted.

On macOS, you have those options: - SIP off (totally, or just driver signature enforcement) - kernel driver (deprecated, Apple doesn’t issue new certs anymore it seems) - system extension (user-mode driver, explicitly intended for device compatibility)

> Apple doesn’t issue new certs anymore it seems This is not true. kexts are still signed by apple after being submitted and vetted.

Apple deprecated KEXTs[1], but still signs some .kexts they've chosen to grandfather in like macFUSE.

[1] https://developer.apple.com/support/kernel-extensions/

Re: Microsoft no longer signs Windows drivers for Process Hacker

#437
post #289

Earlier quoted context omitted.

The issue isn't the TPM, it's who owns the keys to the machine. If the user configures their own keys, it becomes an empowering technology that allows them to verify their boot process hasn't been tampered with. If Microsoft owns the keys, they own the computer and the technology becomes their means of control over the user. They will use this technology to oppressively deny the user their software freedom while simu…

Insightful analysis, though "oppressively deny" sounds harsh to me. There is not a blatant malice in TCG per se, mainly a neutral desire for control and by proxy profit. The treacherous versus trusted computing debate really does boil down to control. Do we trust vendors to be stewards of control on our platforms? Do we even have a choice? I do not recall giving the keys to anyone, and yet it feels like the person bu…

There is not a blatant malice in TCG per se, mainly a neutral desire for control and by proxy profit.

The originators of the idea were thinking of DRM and came from the content industry. I don't think it's a neutral technology at all.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#438

Earlier quoted context omitted.

I expect professionals to be able to distinguish between the two instead of being suckered into some sort of hive-mind thinking of "all data gathering bad hurr durr". I'm absolutely all for privacy and limiting unnecessary gathering of data. But there's nuances to this discussion and labeling everything that has any amount of telemetry as "Spyware" does not do anyone any good.

https://github.com/dotnet/sdk/issues/6145 My favorite part is when someone figures out "telemetry" includes the MAC address, and the dev team just goes completely silent.

The MAC address is very important for developers. It tells them which GUI elements are accesed, what error messages are common and what features of the program are accessed.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#439

From: https://github.com/processhacker/processhacker/discussions/7... >The existing drivers are compatible with Win11 and haven't been blocked by Microsoft yet... The large majority of changes by Microsoft are limited to restricting the Windows API with signature checks that block competitors software (e.g. CreateWindowInBand, NtQuerySystemInformation, NtQueryInformationProcess to name a few) rather than directly tar…

[deleted]

Re: Microsoft no longer signs Windows drivers for Process Hacker

#440

Earlier quoted context omitted.

I genuinely miss the days of playing with DOS, Windows 9x and then all the excitement of Windows XP. All on my own hardware, which was whatever I could scrape from parents, savings, neighbours. I could do what I wanted with these old PCs. There was an openness that existed in the world of computing. Despite all that was said of Microsoft back then, and much of the complaints about proprietary software were true then…

And I increasingly wonder, were we freer back then because there was still some empathy towards customer needs at Microsoft, or because they were simply stifled from their real intentions by technological limitations? They've been slowly cooking the frog in the background for a while now with the "trusted computing" stuff. It's over a decade old at this point. Back then the userbase was more technical and likely to s…

> ..but then they eventually found out that people could be scared into doing anything by justifications of "security" (regardless of what's being secured, who it's being secured by, and who it's being secured from), and here we are today.

Ah, so they took a page from the politicians' handbook. The same drivel that drives the public to concede privacy and freedom to their hands in the state also applies in private industry (I am thinking of the ominous UK Online Safety Bill). Like it is all the same zeitgeist.

Post reply on HN