Live data from Hacker News

Microsoft terminates VeraCrypt account, halting Windows updates

404media.co

211–220 of 259 posts

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#211
post #30

Earlier quoted context omitted.

And what if that customer wants to run their own firmware, ie after the manufacturer goes out of business? "Security" in this case conveniently prevente that.

Tradeoffs. Which is more likely here? 1. A customer wants to run their own firmware, or 2. Someone malicious close to the customer, an angry ex, tampers with their device, and uses the lack of Secure Boot to modify the OS to hide all trace of a tracker's existence, or 3. A malicious piece of firmware uses the lack of Secure Boot to modify the boot partition to ensure the malware loads before the OS, thereby permanent…

> 2. Someone malicious close to the customer, an angry ex, tampers with their device, and uses the lack of Secure Boot to modify the OS to hide all trace of a tracker's existence, or

Lol security people are out of their mind if they think that's actually a relevant concern.

> 3. A malicious piece of firmware uses the lack of Secure Boot to modify the boot partition to ensure the malware loads before the OS, thereby permanently disabling all ability for the system to repair itself from within itself

Oh no so now the malware can only permanently encrypt all the users files and permanently leak their secrets. But hey at least the user can repair the operating system instead of having to reinstall it. And in practice they can't even be sure about that because computers are simply too complex.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#212

Earlier quoted context omitted.

1. P(someone wants to run their own firmware) 2. P(someone wants to run their own firmware) * P(this person is malicious) * P(this person implants this firmware on someone else’s computer) 3. The firmware doesn’t install itself Yeah I think 2 and 3 is vastly less likely and strictly lower than 1.

As an embedded programmer in my former life, the number of customers that had the capability of running their own firmware, let alone the number that actually would , rapidly approaches zero. Like it or not, what customers bought was an appliance, not a general purpose computer. (Even if, in some cases, it as just a custom-built SBC running BusyBox, customers still aren't going to go digging through a custom network…

The customers don't have to install the firmware themselves, they can have a friend do it or pay a repair shop. You know, just like they can with non-computerized tools that they don't fully understand.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#213

Earlier quoted context omitted.

1. P(someone wants to run their own firmware) 2. P(someone wants to run their own firmware) * P(this person is malicious) * P(this person implants this firmware on someone else’s computer) 3. The firmware doesn’t install itself Yeah I think 2 and 3 is vastly less likely and strictly lower than 1.

I encourage you to re-evaluate this. How many devices do you (or have you) own which have have a microcontroller? (This includes all your appliances, your clocks, and many things you own which use electricity.) How many of these have you reflashed with custom firmware? Imagine any of your friends, family, or colleagues. (Including some non-programmers/hackers/embedded-engineers) What would their answers be?

I would reflash almost all my appliances if I could do so easily since they all come with non-optimal behavior for me.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#214

Earlier quoted context omitted.

1. P(someone wants to run their own firmware) 2. P(someone wants to run their own firmware) * P(this person is malicious) * P(this person implants this firmware on someone else’s computer) 3. The firmware doesn’t install itself Yeah I think 2 and 3 is vastly less likely and strictly lower than 1.

On Android, according to the Coalition Against Stalkerware, there are over 1 million victims of deliberately placed spyware on an unlocked device by a malicious user close to the victim every year. #2 is WAY more likely than #1. And that's on Android which still has some protections even with a sideloaded APK (deeply nested, but still detectable if you look at the right settings panels). As for #3; the point is that…

> And that's on Android which still has some protections even with a sideloaded APK (deeply nested, but still detectable if you look at the right settings panels).

Exactly, secure boot advocates once again completely miss that it doesn't protect against any real threat models.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#215
post #147

Earlier quoted context omitted.

Does your Librem 5 run banking apps, though?

Waydroid allows to run Android apps that don't require SafetyNet. If your bank forces you into the duopoly with no workaround, it's a good reason to switch.

And you only have that option as long as people oppose that secure boot enabled dystopia.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#216

Earlier quoted context omitted.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the PRODUCER; id est provide guarantees to the PRODUCER that the firmware of the device they SELL has not been tampered with at some point in the PROFIT chain.

[deleted]

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#217
post #49
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

If only people didn't install Ask Jeeves toolbars all over the place and then asked their grandson during vacations to clean their computer.

Hey I made some good money from that as a kid. And some of the malware that people ended up with was also fairly visually pleasing to a teenager.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#218
post #120
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

> I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security For home/business users I'd agree. But in Embedded / money-handling then it's a life-saver and a really important technology.

If by "really important technology" you mean it lets companies save a bit on fraud-related expenses then sure. But the world worked just fine with much simpler solutions because secure boot or not we have plenty of ways to discourage most people from committing crimes.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#219
post #125
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

This is like saying you shouldn't vaccinate your kids because no one gets polio anymore

We we don't just pump our kids with any vaccine ever developed "just in case" either. Instead we weight actual risk against possible side effects - a concept most security people seem to be unable to grasp.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#220

Earlier quoted context omitted.

It does seem like linux is having its moment right now. there's the money and effort valve is putting into KDE making the steamdeck and steammachine polished for their hardware which helps all users of KDE. cachyos is making having a rolling distro really smooth and snappy on old hardware and making games work mostly ootb. stuff like winboat and wine will let you use the few windows apps you need. you are kinda stuck…

Valve is doing great work. Now… maybe we could condense the 10,000 pointless distros down to a dozen? Oops, nope. Now 10,001, except this one has the menu bar in the middle of the screen and it moves around.

The distros are not pointless. For every one of them there was a human being that wanted something to work differently and the nature of open source let them do it. That should be celebrated and the day we loose that flexibility would be a very sad day.
Post reply on HN