Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

21–30 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#21

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway

What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#22
post #2

Microsoft disabled the developer's certificate so no windows releases can be made.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

Realistically speaking - anything could be a reason. A shakedown or blocking based on some "nudge" (this might come across as tin-foiled though). Some flag/trip-wires going wrong, more worryingly due to a bug/false alarm - and this is more worrying because in this case semi-incompetent large orgs like MSFT find it really hard to accept it, fix, and move on. Some change in OP's account that either they don't see or haven't realised - some edge case, you never know.

And of course, it doesn't affect their earnings and there are no consequence, or significant, so they won't care and won't respond or tell what went wrong.

Can one move legally? Sure. But then it effectively is a combo of who blinks first and who can hold their breath longer.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#23

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

We need better OSes such that signing of software is not required to keep your computer safe.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#26
post #21

Earlier quoted context omitted.

Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway

What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.

Misplaced trustworthiness?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#27

It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.

That's what VeraCrypt is, a fork of the original TrueCrypt after all drama, security doubts, and eventual discontinuation. It took a long time and two independent audits to establish trust in it.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#28
post #2

Microsoft disabled the developer's certificate so no windows releases can be made.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

There's more to it. Signed desktop software can be signed by any CA.

Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines.

In general this isn't your problem.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#29
post #25

Microsoft doing everything in their power to be assholes, as always

As much as I like bashing Microsoft, never underestimate people's capacity for incompetence, especially where large organizations are involved. I don't see how they would gain anything from this move.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#30

That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game…

[dead]
Post reply on HN