Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

111–120 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#111

Earlier quoted context omitted.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

There's more to it. Signed desktop software can be signed by any CA. Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines. In general this isn't your problem.

Speculation as well and highly unlikely. Microsoft drivers can very well BSOD your machine as well, not a significant or convincing threat scenario and certainly not something that lead to certificate revocation of driver developers. There is zero quality control or review by Microsoft here. Not for their own products and not for third party ones.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#112
post #50
post #24

I am somewhat also concerned that this software was still being distributed on SourceForge.

Yes, I stopped using SourceForge after they started tampering with installers to put adware inside of them. It's a bit worrying that a sensitive app such as VeraCrypt is still distributed there.

[deleted]

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#113
post #64
post #24

I am somewhat also concerned that this software was still being distributed on SourceForge.

Why?

~2015, "DevShare". They wrapped open-source software downloads with opt-out adware and PUPs (potentially unwanted programs), without the original developers' consent in some cases. They took over abandoned/unmaintained projects (like GIMP for Windows, VLC, etc.) and replaced the original download with their adware-wrapped version.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#114
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

Or more likely, some automated security system flagged popular but suspicious apps for further review.

Automated systems breaking things without any human contact to get them resolved seems to be the theme of the last 10 years.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#116

That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game…

That's kind of crazy. Why doesn't Microsoft revoke such certs such that you can't sign new software with it?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#117
post #54
post #29

Earlier quoted context omitted.

As much as I like bashing Microsoft, never underestimate people's capacity for incompetence, especially where large organizations are involved. I don't see how they would gain anything from this move.

It doesn’t help that they do that sort of shits AND mandate a microsoft account for logging in to windows. Also how much trust can you have that if you move your business to azure they will not randomly kill it. Incompetence or malice, almost doesn’t matter to the average user.

The outcome is the same, yes. With incompetence, there is at least a glimmer of hope things will get rectified. But you are correct, trust is destroyed this way, and it doesn't look like Microsoft cares much.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#118

Earlier quoted context omitted.

There's more to it. Signed desktop software can be signed by any CA. Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines. In general this isn't your problem.

Speculation as well and highly unlikely. Microsoft drivers can very well BSOD your machine as well, not a significant or convincing threat scenario and certainly not something that lead to certificate revocation of driver developers. There is zero quality control or review by Microsoft here. Not for their own products and not for third party ones.

Exhibit A:

https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_ou...

Post reply on HN