Live data from Hacker News

Microsoft terminates VeraCrypt account, halting Windows updates

404media.co

131–140 of 259 posts

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#131

Earlier quoted context omitted.

They shouldn't _have_ to do anything. The point is that no demands should be placed upon users. Same problem with age gating. It's fine, as long as zero additional demands are placed upon users.

Freedom from the consequences of malware is more valuable than the low cost of turning SecureBoot off if you don’t want it. We shouldn’t need the hassle of locks on our home and car doors, but we understand they are probably worthwhile for most people.

Do you lock your house or car and permanently handover the keys to some stranger, who you then have to depend on always to lock or unlock it for you?

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#132

Earlier quoted context omitted.

They shouldn't _have_ to do anything. The point is that no demands should be placed upon users. Same problem with age gating. It's fine, as long as zero additional demands are placed upon users.

Freedom from the consequences of malware is more valuable than the low cost of turning SecureBoot off if you don’t want it. We shouldn’t need the hassle of locks on our home and car doors, but we understand they are probably worthwhile for most people.

What's the improved security argument for terminating VeraCrypt's account though? SB does have clear benefits but what is unclear is the motivation for the account termination.

What's the likelihood that this account ban provides zero security benefit to users and was instead a requirement from the gov because Veracrypt was too hard to crack/bypass.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#133
post #126

This is precisely why we can't allow platform-owners to be the arbiters of what software is allowed to run on our devices. Any software signing that is deemed to be crucial for ensuring grandma-safety needs to be delegated to independent third parties without perverse incentives. This is what the Digital Markets Act is supposed to protect developers against. Have there been any news regarding EU's investigation into…

There is nothing stopping you from using third party certificates to sign Windows binaries. It's just expensive. You don't even need a MS toolchain or CLI tool for it.

> “Users who have enabled system encryption with VeraCrypt may face boot issues after July 2026 because Microsoft will revoke the [certificate authority] that was used to sign the VeraCrypt bootloader,” Idrassi said. “A new Microsoft CA must be used for bootloaders to continue working.”

> Without access to the Microsoft account used for sending software updates, “I will not be able to apply the required new signature to VeraCrypt, making it impossible to boot.”

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#134
post #127
post #86

Earlier quoted context omitted.

you click the box to turn off secure boot

...and then some essential software you need to run detects that and refuses to run. See where the problem is here?

It does no such thing if you enrol your own keys using the extremely well documented process to do that.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#135

Earlier quoted context omitted.

Freedom from the consequences of malware is more valuable than the low cost of turning SecureBoot off if you don’t want it. We shouldn’t need the hassle of locks on our home and car doors, but we understand they are probably worthwhile for most people.

Do you lock your house or car and permanently handover the keys to some stranger, who you then have to depend on always to lock or unlock it for you?

No? I have locks on my house and car that I have the keys for. That an argument _for_ secure boot.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#136
post #91
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

I strongly disagree on the Secure Boot front. It's necessary for FDE to have any sort of practical security, it reduces malicious/vulnerable driver abuse (making it nontrivial), bootkits are a security nightmare and would otherwise be much more common in malware typical users encounter, and ultimately the user can control their secure boot setup and enroll their own keys if they wish. Does that mean that Microsoft do…

Full disk encryption protects from somebody yanking a hard drive from running server (actually happens) or stealing a laptop. Calling it useless because it doesn't match your threat model... I hate todays security people, can't threat model for shit.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#137
post #64

Earlier quoted context omitted.

Clearly you’ve never met my ex’s (or a past employer). Not even being sarcastic this time.

You expect that stuff to happy with 3 letter agencies.

Sorry, I have no idea what you are trying to say.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#138
post #99

Earlier quoted context omitted.

But...it doesn't restrict user freedom. If the user wishes to do so, they can disable SB.

They shouldn't _have_ to do anything. The point is that no demands should be placed upon users. Same problem with age gating. It's fine, as long as zero additional demands are placed upon users.

Users who care enough to do so can enrol their own keys using the extremely well documented process to do that.

Users who don’t care about the runtime integrity of their machine can just turn it off.

Both options are so easy that you could’ve learned how to do them on your machine in the time that you spent posting misinformation in this thread.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#139

Earlier quoted context omitted.

You can set up custom SecureBoot keys on your firmware and configure Linux to boot using it. There's also plenty of folks combining this with TPM and boot measurements. The ugly part of SecureBoot is that all hardware comes with MS's keys, and lots of software assume that you'll want MS in charge of your hardware security, but SecureBoot _can_ be used to serve the user. Obviously there's hardware that's the exception…

> You can set up custom SecureBoot keys on your firmware and configure Linux to boot using it. Right, but as engineers, we should resist the temptation to equate _possible_ with _practical_. The mere fact that even the most business oriented Linux distributions have issues playing along SecureBoot is worrying. Essentially, SB has become a Windows only technology. The promise of what SB could be useful for is even mud…

[dead]

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#140
post #127

Earlier quoted context omitted.

...and then some essential software you need to run detects that and refuses to run. See where the problem is here?

It does no such thing if you enrol your own keys using the extremely well documented process to do that.

It's fair to think of secure boot in only the PC context but the model very much extends to phones. It seems ridiculous to me that to use a coupon for a big mac I have to compromise on what features my phone can run (either by turning on secure boot and limiting myself to stock os or limiting myself to the features and pricing of the 1 or 2 phones that allow re-locking).
Post reply on HN