Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

11–20 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#13
post #2

Microsoft disabled the developer's certificate so no windows releases can be made.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

This is a concern and risk that has realised itself multiple times over the past decades. There have been multiple stories linked to multiple developers in the past.

If you publish to any closed platform including ios, mac, win, android, this is the risk you run and a condition of operating you will need to accept.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#14

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#15
post #8
post #5

Earlier quoted context omitted.

Might be it even not using all your code to train AI. Or at least not asking your explicit permission to do it.

sourceforge was always very scummy, I think they would definitely use the code for that if they could

It wasn’t always scummy… but there was a definite shift after they got bought. It’s kept getting worse since then.

Then again, this was something like 20 years ago. Back then, Sourceforge was something closer to GitHub today. It was the de facto public source repository. You could even get an on-premise version, IIRC.

Actually, this is sounding a lot like GitHub these days… not sure what that means.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#16
post #6

They need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.

I blew the lid on X today:

https://x.com/i/status/2041698657368703484

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#18
post #5

Jesus, sourceforge is still on the go?

Might be it even not using all your code to train AI. Or at least not asking your explicit permission to do it.

Not every conversation has to be a conversation about AI.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#20
That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game no longer launches on a computer using a driver with that certificate. Microsoft however does not do this and malware developers can then simply use the certificates for their own purposes. So all this nonsense is basically just a restriction on regular users and honest developers while the “bad guys” can get around it.
Post reply on HN