Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

121–130 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#122
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

[flagged]

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#123
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

likely chose to shut down rather than bend over, same as Lavabit a year prior. I find it more plausible than the other theory.

Fair assumption, but unlike Lava, TC never had customer/user data. The NSL/forced shut down theories also make little sense to me however, the fork was up by the end of the week and was easy to foresee. Kinda why this fascinates me so much, no theory I ever read survives basic scrutiny. Perhaps some things, we’ll never know.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#124
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

The other day I tried to create a Github account and was repeatedly told I am fraudulent. Nothing else. Try again later, it says.

This is the same thing that's happened every time I've tried to have a Microsoft account. I don't think Microsoft wants to have customers who aren't rich.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#125
post #77

Earlier quoted context omitted.

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

Agree. Single point of failure. One developer, one account. Crazy.

You're not actually allowed to avoid this by having multiple accounts, that falls under "ban evasion".

But yes, there's a lot of critical single maintainer projects.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#126

Earlier quoted context omitted.

Maybe time for a custom license that would require M$ to sign up for special T&Cs if they want to use this software? Who cares if it's OSI-approved or not, a line saying "M$, Google, and the like need written permission for every use case" would help to make those leeches honest. Just learn from the JSLint example.

We literally just did this. Now we have Valkey. Nobody won.

Did anyone lose?

Valkey is better because all of the new development work happens on Valkey, not because of the license. If the actual developer changed the license, that would be a different situation.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#127
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

likely chose to shut down rather than bend over, same as Lavabit a year prior. I find it more plausible than the other theory.

I went on a Wikipedia dive and discovered this funny bit regarding the court process surrounding Lavabit and FBI's desire of the TLS private keys.

> The contempt of court was caused by Levison providing the keys printed in a tiny (4 point) font, which was deemed "largely illegible" by an FBI motion, which went on to complain that "To make use of these keys, the FBI would have to manually input all 2560 characters, and one incorrect keystroke in this laborious process would render the FBI collection system incapable of collecting decrypted data."

(And to be clear, that's all they ever saw of said keys)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#128

Seeing this kind of friction makes me more confident in VeraCrypt. The tools that never seem to run into trouble with platform gatekeepers are the ones I'd worry about.

The biggest risk in encryption software is that you lose access to your data. You seem to be ignoring that risk completely and focusing on something else entirely.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#129
post #97
post #66

Forced software signing should be illegal.

It's not forced, especially for normal software, you just get a popup. It's a bit of a pain to disable the requirement for drivers, though.

I don't think you can install VeraCrypt, at least for system encryption, unless the installer is signed
Post reply on HN