Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

511–520 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#511

Earlier quoted context omitted.

Ah, yes: Hello, My name is [Kumar/Numan/Punith/Suresh/Sachin] and I work with the Outlook.com Sender Support Team. I do not see anything offhand for the IP (xx.xx.xx.xx) that would be preventing your mail from reaching our customers. Good bye and fuck off. In response to complaining that their servers say - 550 5.7.1 Unfortunately, messages from [xx.xx.xx.xx] weren't sent. Please contact your Internet service provide…

At least you got a response! Most people don't. According to some previous blogposts and threads on this topic, apparently if you just contact them often enough, they will after a few months escalate the problem to the competent team and get you unblocked.

Yes, I've done this successfully several times. It usually takes several tries though.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#512
post #469

Earlier quoted context omitted.

> Epic was simply using their keys to sign software that they had agreed not to sign. Epic never abused their desktop signing keys, which are stated to be for security only, what are you talking about? Apple did more than that too, they also briefly pulled their Apple logins, which they had surprise mandated on everyone who allowed third party logins. They went full mask off.

It is downright pathetic of you to attempt to differentiate between desktop and mobile signing keys. Epic made it clear that they can’t be trusted with any kind of signing keys.

Apple made a distinction for desktop that the keys there were to be for security only. The iOS stuff was a payment/business dispute, not security related.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#513

Earlier quoted context omitted.

I expect professionals to be able to distinguish between the two instead of being suckered into some sort of hive-mind thinking of "all data gathering bad hurr durr". I'm absolutely all for privacy and limiting unnecessary gathering of data. But there's nuances to this discussion and labeling everything that has any amount of telemetry as "Spyware" does not do anyone any good.

https://github.com/dotnet/sdk/issues/6145 My favorite part is when someone figures out "telemetry" includes the MAC address, and the dev team just goes completely silent.

You forgot a pretty relevant part:

Hashed MAC address: a cryptographically (SHA256) anonymous and unique ID for a machine.

Although I disagree that they should have this to begin with, it being anonymized is still a pretty important detail.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#514

Earlier quoted context omitted.

You are supposed to store the recovery key(s) in a secure location. Then if you lose your 2FA device, you can reset your 2FA from those recovery keys.

What secure location? My sock drawer? Or am I expected to go buy a safety deposit box? I'm really not that organized and I loose slips of paper all the time, it's a major reason I was drawn to computers growing up.

Sock drawer, wallet, locally on your computer, wherever. If the recovery keys are compromised, that really just downgrades your 2FA back to 1FA.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#515
post #249

Earlier quoted context omitted.

> Can't remember last time I saw this type of malware in the wild. That's exactly because widespread secure boot has made it impractical! As for niche Linux distros, it's been mandated since the beginning that you can install your own Secure Boot keys on Microsoft certified desktop platforms.

That branch of malware was already rare when uefi secure boot was introduced. > it's been mandated since the beginning that you can install your own Secure Boot keys on Microsoft certified desktop platforms. ...on x86; on ARM they mandated that the user couldn't install their own keys, which shows that they will lock users out as much as they think they can get away with.

It hasn't been mandated at all. A number of years ago, Microsoft made headlines by changing their policy to get rid of that mandate. See https://arstechnica.com/information-technology/2015/03/windo... . Microsoft's page at https://docs.microsoft.com/en-us/windows-hardware/manufactur... says that you can "usually" disable it, so I don't think they've changed their policy since then.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#516

Earlier quoted context omitted.

I completely agree with your points. > I don't feel the same way towards my garden hose or washing machine. We just built and furnished a remote vacation home from the ground up and the shiny new appliances and even some fixtures (mostly ordered or approved by my wife) default to stubbornly demanding cloud access, often before they will even perform their most basic functions. At the moment, internet is only via 4G h…

Well, when the story began I though this sounds like a pleasant getaway, and I was happy to read you've acquired such a place. Then the rest of it was just a dour decline. Man, oh man. The worst of it is that all these devices could integrate genuine 'smart' functionality, but a user-respecting way would be locally run from a central box with open and interoperable protocols across devices. Exactly how a router and s…

It's still going to be a pleasant getaway, just one requiring much more effort during set up to configure it in a long-term sustainable way.

> There is just so much passivity now.

For anyone interested there is a large, active online community around the open-source Home Assistant platform. I'm using it and the community has been a terrific resource for finding those still too-rare devices which both work well and are willing to work sans-cloud. There are thousands of contributors and hundreds of thousands of HA users now and together we comprise a market large enough for even low-cost Asian manufacturers to notice and start targeting products toward.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#517
post #438

Earlier quoted context omitted.

The MAC address is very important for developers. It tells them which GUI elements are accesed, what error messages are common and what features of the program are accessed.

For some reason developers think they're magically exempt from judgement of their data harvesting. I don't want you monitoring my activity on my goddamn devices, however much you yammer on about having good intentions. The act itself is hostile, and that's why developers are so goddamn sneaky about it. You're invading privacy and creating metadata records that are trivially deanonymized. There's an honest, non sneaky…

From what I've seen the invasive data harvesting often does not come from developers themselves, but is rather requested by product and BI wanting to get more insights into the customers.

It's hard to really stand up to that kind of situation.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#518

Earlier quoted context omitted.

What secure location? My sock drawer? Or am I expected to go buy a safety deposit box? I'm really not that organized and I loose slips of paper all the time, it's a major reason I was drawn to computers growing up.

Sock drawer, wallet, locally on your computer, wherever. If the recovery keys are compromised, that really just downgrades your 2FA back to 1FA.

I’m not concerned about the keys being compromised, I’m concerned about loosing them, since the idea is they’re unneeded for many years and then suddenly become essential.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#519
post #445

Earlier quoted context omitted.

Personally I think the practical solution is companies like frame.work & valve making open hardware and creating software shims like proton because it's part of their value prop and business model to make open hardware. If valve doesn't make Linux a viable gaming platform, they are going to be chess maneuvered into a checkmate by MSFT and Apple. Epic recognizes a similar issue too which is why even if they are compet…

> I think the practical solution is companies like frame.work & valve making open hardware and creating software shims like proton Right. I admire them certainly, and I'm thinking about getting a framework laptop myself, but we shouldn't really call their products free/open hardware because they use backdoored CPUs from Intel/AMD

They are not currently, because they are forced by current reality to use things like that. But they create the market demand to make open CPUs in the first place. If you become a big enough customer, Intel and AMD start becoming interested in making open versions of their firmware or CPUs, like they do with game consoles today, making custom models just for them. Framework is already interested in making an ARM laptop for example too, and I could foresee them getting AMD to make an open firmware version their CPUs just for the high assurance / open hardware segment that is starting to get created by valve and framework.

Create market demand, and companies start providing market solutions.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#520
post #66

Earlier quoted context omitted.

> Microsoft have their keys in the default keychain because they bothered to be involved in the process, unlike linux companies like Redhat. The status quo was that systems could boot any operating system the user wanted. Microsoft tried to force OEMs to lock operating systems other than those on a very short list (they tried to force Secure Boot to be enabled with no way for users to turn it off, and you can confirm…

There are two sides to this coin. Firstly there's the hardware vendors who make firmware, who decided to incorporate UEFI presumably because intel pushed it hard (original efi booted itanium and is also found in older Macs). But it was certainly possible for a Linux vendor to have got a key into the kek and dB lists: https://mjg59.dreamwidth.org/12368.html That's from Matthew Garrett, who along with Peter Jones, were…

>But it was certainly possible for a Linux vendor to have got a key into the kek and dB lists: https://mjg59.dreamwidth.org/12368.html

Your text is written in past tense. But if there is a maintained list why is nobody working to get linux vendor keys in now? Yeah, it'll take a while for the hardware cycle to refresh, but it's better than nothing.

Post reply on HN