Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

161–170 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#161
post #151
post #146

Earlier quoted context omitted.

and yet... still unusable by the mass majority of people.

This isn't really true anymore with the advent of Flatpak & Flathub. It's just an app store like any other platform. Even the majority of games work without tweaking.

I've run Linux as a daily driver recently Flatpak and Flathub still break all the time. Not to mention the last time I bumped my Nvidia drivers nothing decided to open anymore.

Any OS that requires even once going to the command line is unusable for 99% of the population (and for me I just shouldn't ever have to).

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#162
post #81
post #6

They need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.

It's much worse than you think. Press coverage -> manual intervention is at best a bandaid covering up a major wound in a flaw that happens with independent software distribution. The old model where the user decides which software or apps to run on their machine, is basically already replaced by a whitelist system that is managed by companies who have no interest or obligation to approve developers. Factors like ”be…

Some countries (the EU in general) are already doing things about this. Owning the app store means you are a monopoly and now the only question is are you illegal by the local laws which vary.

You can/should write your congressman (or whatever they are called in your country) and get better laws in place.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#163
post #146

Earlier quoted context omitted.

and yet... still unusable by the mass majority of people.

My kids grew up on Gnome essentially, I can tell you Win11 is a lot more confusing to them, not just because because they grew up on Gnome, there is just so much more ... stuff. And notifications and flashy things and news and weather apps and they all want your attention. Gnome is much more iPadOS like (minus that horrible concoction called the App Store). Sure, if you're all in on MS365 (like all schools here in th…

And someone once raised their kids speaking Klingon, that isn't a good excuse on why it's a language others should use.

For the vast majority of people MS365 is a requirement, but really the issue is that even minor fixes require the command line on Linux and that makes it unusable.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#165
post #146
post #115

Linux is the only hope at this point for the future of computing. Windows and macOS are just too risky to do any business with. Waste of all resources.

and yet... still unusable by the mass majority of people.

Not used does not mean not usable. Primary school aged children used MS-DOS without any documentation in 1990's. Pretty sure randomly selected people would be able to use modern Linux distro, when pre-installed just like windows are.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#166
post #37

Earlier quoted context omitted.

You can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.

Note that signatures are not revoked retroactively when a certificate is revoked. You can still install previous releases.

With all the bugs and potential security flaws that are there and not fixable.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#167
post #40
post #4

It's like LibreOffice all over again: https://www.neowin.net/news/microsoft-bans-libreoffice-devel...

This is worrying on many levels. So Microsoft force you to create an account to use Windows and then they reserve the right to block you from your own account, thereby potentially making you lose access to all your OWN data. This is crazy and yet another reason to stop using Windows as soon as possible.

I know it's not what people want to hear but my response to a lot of the comments here is just a general, I agree, it's time to stop using Windows.

They won't let you secure your drive the way you want. They won't let you secure your network the way you want (per the top-level comment about Wireguard). In so doing they are demonstrating not just that they can stop you from running these particular programs but that they are very likely going to exert this control on the entire product category going forward, and I see little reason to believe they will stop there. These are not minor issues; these are fundamental to the safety, security, and functionality of your machine. This indicates that Microsoft will continue to compromise the safety, security, and functionality of your machine going forward to their benefit as they see fit. This is intolerable for many, many use cases.

I think it is becoming clear that Microsoft no longer considers Windows users to be their customers any more. Despite the fact that people do in fact pay for Windows, Microsoft has shifted from largely supporting their customers to out-and-out exploiting their customers. (Granted a certain amount of exploitation has been around for a long time, but things like the best backwards compatibility in the industry showed their support, as well.)

I suspect this is the result of a lot of internal changes (not one big one) but I also see no particular reason at the moment to expect this to change. To my eyes both the first and second derivative is heading in the direction of more exploitation. More treating users like a cattle field and less like customers. When new features or work is being proposed at Microsoft, it is clear that it is being analyzed entirely in terms of how it can benefit Microsoft and users are not at the table.

No amount of wishing this wasn't so is going to change anything. No amount of complaining about how hard it is to get off of Windows is going to change anything; indeed at this point you're just signalling to Microsoft that they are correct and they can treat you this way and there's nothing you will do about it for a long time.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#168
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

[flagged]

I have a hard time believing this to be true when for a while now it's always been some automated system that goes completely unchecked and unmonitored. It's not until someone who is wrongfully affected complains on Xitter does anyone notice.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#169

That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game…

That's kind of crazy. Why doesn't Microsoft revoke such certs such that you can't sign new software with it?

Because it's mostly just performative.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#170
post #95
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

It's more or less commonly accepted that its creator got jailed for being an arms dealer. https://en.wikipedia.org/wiki/Paul_Le_Roux

Makes you wonder what kind of leverage/information you have to have to only get 25 years for admitting to being involved in 7 murders.
Post reply on HN