Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

231–240 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#232

Earlier quoted context omitted.

> Microsoft doesn't want to allow software that would allow the user to shield themselves I don't think Microsoft cares (about anything besides making mo' money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. No tinfoil needed.

>I don't think Microsoft cares (about anything else than making money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. Microsoft the corporation may only care about making money, but a lot of very high ranking folks within MS Security aren't just friendly to intelligence agencies, they take genuine pride in helping intelligence agencies. They'…

I can completely believe this.

I was always convinced that Skype was bought by microsoft so CIA/US intelligence agencies to have listening capabilities.

The first thing Microsoft did after the Skype purchase was making it easier to tap into the calls by removing p2p calling and routing calls using centralized servers.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#233
post #59

Looks like Linux and some of the BSDs are the only remaining truly open OSes.

Until Microsoft decides to no longer sign the Linux boot loader shim (for IBM/Red Hat, no less).

In most cases you can put your computer secure boot in setup mode and roll your own keys.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#234
post #158

Earlier quoted context omitted.

I don't think you can install VeraCrypt, at least for system encryption, unless the installer is signed

According to further up the thread, you can if you disable secureboot.

And you mess with your boot.ini and ignore that half your screen is taken up by a TEST MODE banner. Buy a screen twice as big and tape over half of it, I guess.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#235
post #67

Earlier quoted context omitted.

the current law requires no verification at all simple attestation, you could put in _any_ age. it also does not effect linux distros as a whole, only distros in jurisdictions with the laws.

Sure, for now... I simply don't believe it will stop at "simple attestation", because we all know that simple attestation is practically useless, but once the various distros accept this "trivial" inconvenience, "Age verification 2" with harsher requirements will soon be on the way. I would be ecstatic to be proved wrong on this, but experience tells me that is not likely to happen.

Simple attestation is very useful for the case where a parent gives a child access to a computer and wants that computer to block porn. That's the use case everyone is clamoring for, and asking the root user "how old is this user?" solves it in a simple, open, privacy-preserving way. Everybody wins, except the teenager who wants to watch porn. If this were not legally mandated, everyone would support it as a useful feature, but since it is legally mandated, we have to get angry about it.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#236
post #179
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Encouraged by this thread, I tweeted about it: https://x.com/EdgeSecurity/status/2041872931576299888

If someone was a bad actor, right now would be a pretty good time to start exploiting zero days in WireGuard…

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#237

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

We need better OSes such that signing of software is not required to keep your computer safe.

With a file system driver like Veracrypt, if it’s malicious, the OS might keep your computer safe, but not your files that you store in that file system.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#238
post #64

Earlier quoted context omitted.

Why?

~2015, "DevShare". They wrapped open-source software downloads with opt-out adware and PUPs (potentially unwanted programs), without the original developers' consent in some cases. They took over abandoned/unmaintained projects (like GIMP for Windows, VLC, etc.) and replaced the original download with their adware-wrapped version.

Note that it's meaningless to call out "PUPs" as that category includes many things that are developed and distributed on sourceforge, like torrent clients.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#239
post #99

Seeing this kind of friction makes me more confident in VeraCrypt. The tools that never seem to run into trouble with platform gatekeepers are the ones I'd worry about.

That seems like a very nonsensical stance.

Well look at something like ANOM. The FBI encouraged its use. Because it was run by the FBI and they could see all the private messages.

If Veracrypt was a honeypot, the powers that be would go out of their way to make it as easy to use as possible. They'd instantly sack whoever made this decision, and reverse it.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#240
post #98

prediction: they are testing the waters. If there is enough outcry they will go "oopsie whoopsie, hehe :3 your account is restored". If there isn't enough outcry they will go forward and disable more signing keys related to things like torrent clients, VPN software, eject UBO from the edge store etc etc. Atleast now I'm a bit more certain that VC is indeed safe.

They've finally sprung their enshittification trap. Their move into "open source" was never of friendly origin. It was a business move, plain and simple.

And now they're locking down Window OS, hard. Expect github and vscode to follow.

Post reply on HN