Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

101–110 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#101
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

> Microsoft doesn't want to allow software that would allow the user to shield themselves I don't think Microsoft cares (about anything besides making mo' money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. No tinfoil needed.

>I don't think Microsoft cares (about anything else than making money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues.

Microsoft the corporation may only care about making money, but a lot of very high ranking folks within MS Security aren't just friendly to intelligence agencies, they take genuine pride in helping intelligence agencies. They're the kinds of people who saw nothing wrong or objectionable with PRISM whatsoever, they were just mad they got caught, and that the end user (who they believe had no right to even know about it) found out anyway. The kind of people who openly defend the legitimacy of the FISA court.

This aren't baseless accusations, this comes from first-hand experience interacting with and talking to several of them. Charlie Bell literally kept a CIA mug on a shelf behind him, prominently visible during Teams calls, as if to brag.

Remember - Microsoft was the very first company on the NSA's own internal slide deck depicting a timeline of PRISM collection capabilities by platform, started all the way back in 2007. All companies on that slide may have been compelled to assist with national security letters. Some were just more eager than others to betray the privacy and trust of their own customers and end-users.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#102
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

likely chose to shut down rather than bend over, same as Lavabit a year prior. I find it more plausible than the other theory.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#103
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

I would also like to know why is it excluded from Archive.org

https://web.archive.org/web/20260000000000*/https://www.true...

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#105
post #95
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

It's more or less commonly accepted that its creator got jailed for being an arms dealer. https://en.wikipedia.org/wiki/Paul_Le_Roux

I knew the speculation on him being involved in some capacity, but as the wiki page states, this was never confirmed in any substantial way.

More importantly, if development seized with no public comment, that would be one thing and may strengthen the "he got arrested" theory. However, there was some final communication, specific recommendations to rely on Bitlocker of all things, a new version of Truecrypt was released solely for decrypting existing disks and then the web page was removed, including a flag set on robots.txt to ensure it wouldn't appear on archive.org. All this concurrent to a crowd funded source code audit that, in the end, did not find any server issues or backdoors (I recall some speculation back in the day, that either known code quality issues or an intentional backdoor could have caused the exodus).

That all makes it hard to link this to an arrest of the main developer, though I dislike speculation without any hard evidence and if there is no new information, I'll keep this filed under "there is no answer".

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#106
post #52

maybe an old vulnerable signed driver can be used to load the new version :D. on a more seirous note, i think contact with a person at MS, likely via socials triggering that, might help here. It all depends on the reason for the ban/block/cancel. if they had a reason other than 'oops mistake' its likely just going to remain in place. (sadly, that is how MS is. if you care for privacy maybe go to BSD)

Who said vulnerable? Perhaps just a driver with less features.

GP refers to the practice of getting kernel level code execution using other, old vulnerable drivers and using it to run the VC driver.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#107
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

Or more likely, some automated security system flagged popular but suspicious apps for further review.

Where are the people that tried to sell us software signatures as security benefit? The reality is that they are a very specific security problem. In theory and in practice.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#108

Earlier quoted context omitted.

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

Maybe time for a custom license that would require M$ to sign up for special T&Cs if they want to use this software? Who cares if it's OSI-approved or not, a line saying "M$, Google, and the like need written permission for every use case" would help to make those leeches honest. Just learn from the JSLint example.

We literally just did this. Now we have Valkey. Nobody won.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#109
post #77

Earlier quoted context omitted.

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

Agree. Single point of failure. One developer, one account. Crazy.

No, that is not the issue here. The source of the problem is something different. This is a wrong root cause analysis.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#110
post #37

Earlier quoted context omitted.

You can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.

Afaict, you can't disable driver signature enforcement permanently without disabling secure boot.

Secure boot is an anti-feature in most of the landscape anyway. Sure, if you have a distribution under your control or influence it could theoretically be a benefit. But you need to not be stupid or naive here.

You can also roll you own encryption if you are not stupid and naive. Probably a question of self-reflection.

Post reply on HN