Live data from Hacker News

Microsoft terminates VeraCrypt account, halting Windows updates

404media.co

121–130 of 259 posts

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#121
post #99

Earlier quoted context omitted.

But...it doesn't restrict user freedom. If the user wishes to do so, they can disable SB.

They shouldn't _have_ to do anything. The point is that no demands should be placed upon users. Same problem with age gating. It's fine, as long as zero additional demands are placed upon users.

Freedom from the consequences of malware is more valuable than the low cost of turning SecureBoot off if you don’t want it.

We shouldn’t need the hassle of locks on our home and car doors, but we understand they are probably worthwhile for most people.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#122

Earlier quoted context omitted.

Well, the hope was always that those of us inconvenienced by M$ would all collectively contribute to making Linux distros more convenient for everyone. But we can't ever seem to get inconvenienced enough to actually sufficiently mobilize and/or coordinate such an effort.

It does seem like linux is having its moment right now. there's the money and effort valve is putting into KDE making the steamdeck and steammachine polished for their hardware which helps all users of KDE. cachyos is making having a rolling distro really smooth and snappy on old hardware and making games work mostly ootb. stuff like winboat and wine will let you use the few windows apps you need. you are kinda stuck…

Valve is doing great work.

Now… maybe we could condense the 10,000 pointless distros down to a dozen? Oops, nope. Now 10,001, except this one has the menu bar in the middle of the screen and it moves around.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#123
post #64

Earlier quoted context omitted.

1. P(someone wants to run their own firmware) 2. P(someone wants to run their own firmware) * P(this person is malicious) * P(this person implants this firmware on someone else’s computer) 3. The firmware doesn’t install itself Yeah I think 2 and 3 is vastly less likely and strictly lower than 1.

Clearly you’ve never met my ex’s (or a past employer). Not even being sarcastic this time.

You expect that stuff to happy with 3 letter agencies.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#124
post #85

Earlier quoted context omitted.

The public keys are provided by the developer. Google, or Apple, for example. It's how they know that nothing was tampered with before it left the factory.

Nothing has been tampered with doesn't mean there's no factory backdoor, it just only means same as factory, nothing more.

Apple or Google know what the cryptographic signature of the boot should be. They provide the keys. It's how they know that "factory reset" does not include covert code installed by the factory. That's what we're talking about.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#125
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

This is like saying you shouldn't vaccinate your kids because no one gets polio anymore

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#126

This is precisely why we can't allow platform-owners to be the arbiters of what software is allowed to run on our devices. Any software signing that is deemed to be crucial for ensuring grandma-safety needs to be delegated to independent third parties without perverse incentives. This is what the Digital Markets Act is supposed to protect developers against. Have there been any news regarding EU's investigation into…

There is nothing stopping you from using third party certificates to sign Windows binaries. It's just expensive. You don't even need a MS toolchain or CLI tool for it.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#127
post #86
post #30

Earlier quoted context omitted.

And what if that customer wants to run their own firmware, ie after the manufacturer goes out of business? "Security" in this case conveniently prevente that.

you click the box to turn off secure boot

...and then some essential software you need to run detects that and refuses to run. See where the problem is here?

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#128
post #105
post #30

Earlier quoted context omitted.

And what if that customer wants to run their own firmware, ie after the manufacturer goes out of business? "Security" in this case conveniently prevente that.

Then that customer shouldn't buy a device that doesn't allow for their use case. Exercise some personal agency. Sheesh.

What happens when there are no more devices that allow for that use case? This is already pretty much the case for phones, it's only a matter of time until Microsoft catches up.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#129
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the PRODUCER; id est provide guarantees to the PRODUCER that the firmware of the device they SELL has not been tampered with at some point in the PROFIT chain.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#130

Earlier quoted context omitted.

#2 and #3 are fearmongering arguments and total horseshit, excuse the strong language. Should either of those things happen the bootloader puts up a big bright flashing yellow warning screen saying "Someone hacked your device!" I use a Pixel device and run GrapheneOS, the bootloader always pauses for ~5 seconds to warn me that the OS is not official.

Yes. They're making the point that your flashing yellow warning is a good thing, and that it's helpful to the customer that a mechanism is in place to prevent it from being disabled by an attacker.

No, they've presented a nonsense argument which Apple uses to ban all unofficial software and firmware as if it had some merit.
Post reply on HN