Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

151–160 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#151
post #146
post #115

Linux is the only hope at this point for the future of computing. Windows and macOS are just too risky to do any business with. Waste of all resources.

and yet... still unusable by the mass majority of people.

This isn't really true anymore with the advent of Flatpak & Flathub. It's just an app store like any other platform. Even the majority of games work without tweaking.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#153
post #115

Linux is the only hope at this point for the future of computing. Windows and macOS are just too risky to do any business with. Waste of all resources.

Don't worry, US states are working on making Linux illegal through age verification requirements in the OS.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#154
post #143

Earlier quoted context omitted.

But making money at the expense of people is not a Tinfoil conspiracy - it's a factual statement.

It is also a factual statement, that tinfoil shields (somewhat) from electromagnetic radiation.

But it is NOT necessarily a factual statement that one of the main uses of electromagnetic radiation is for humans to send information over long distances; nor that I first learned about tinfoil hats from some random piece of information that was being broadcast by means of electromagnetic radiation. It's just a vibe.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#155
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

> Microsoft doesn't want to allow software that would allow the user to shield themselves I don't think Microsoft cares (about anything besides making mo' money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. No tinfoil needed.

>I don't think Microsoft cares (about anything besides making mo' money)

If Microsoft amounts to a sentient entity (i.e. is able to care about things), we have a bigger problem.

If we put the wall of metaphor between us and that interpretation, it still remains likely that "users shielding themselves" is of primary concern to Microsoft's bottom line.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#156

Any chance this is the issue? https://techcommunity.microsoft.com/blog/windows-itpro-blog/...

From TFA: "I have encountered some challenges but the most serious one is that Microsoft terminated the account I have used for years to sign Windows drivers and the bootloader."

Yeah, and the first comment beneath that mentions that the most recent version is signed with the "2011 CA" that the article I link to discusses being deprecated.

My guess was that he got caught up in some house-cleaning. My theory being that he's still signing his code the way malware authors also do and got flagged by some automated review that's meant to force him to go get WHCP certified or whatever the new route is.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#157
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

> what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately?

Honestly, anyone still using Windows probably deserves it.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#158
post #97

Earlier quoted context omitted.

It's not forced, especially for normal software, you just get a popup. It's a bit of a pain to disable the requirement for drivers, though.

I don't think you can install VeraCrypt, at least for system encryption, unless the installer is signed

According to further up the thread, you can if you disable secureboot.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#159
post #37

Earlier quoted context omitted.

We can still install, right? It just comes up with a scary warning. Still not great but at least we aren't locked out.

You can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.

Note that signatures are not revoked retroactively when a certificate is revoked. You can still install previous releases.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#160

Earlier quoted context omitted.

There's more to it. Signed desktop software can be signed by any CA. Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines. In general this isn't your problem.

Speculation as well and highly unlikely. Microsoft drivers can very well BSOD your machine as well, not a significant or convincing threat scenario and certainly not something that lead to certificate revocation of driver developers. There is zero quality control or review by Microsoft here. Not for their own products and not for third party ones.

That's not entirely true. Certain classes of signing keys require driver developers to put their driver through a test battery and submit the results to Microsoft.
Post reply on HN