Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

241–250 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#241
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic.

It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues.

There is little hope for getting this through in the US where most politicians of any stripe hate the public, and the ones that don't have hardly any power. But it might be possible to do this in the EU.

Then, we non-EU folks need to apply for Estonian e-residency [1] which may get us EU regulatory coverage.

[1] https://en.wikipedia.org/wiki/E-Residency_of_Estonia

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#242
post #164

https://community.osr.com/t/locked-out-of-microsoft-partner-... Could be a related issue to this? Maybe Microsoft just doesn’t want driver developers for whatever reason.

its my computer. its my os. i own it. I paid my money and bought the program. not them. I am free to install whatever software and modify whatever kernel components as i see fit.

I am so sick and tired of the continued erosion of the ownership model. I dont want to rent anything. But corporations see it as an avenue to increase revenue. We pay more, for less. What else is new.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#243
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

It's got a lot of analogy to restaurants banning Uber delivery for not handling their food to their standards.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#244
post #105
post #95

Earlier quoted context omitted.

It's more or less commonly accepted that its creator got jailed for being an arms dealer. https://en.wikipedia.org/wiki/Paul_Le_Roux

I knew the speculation on him being involved in some capacity, but as the wiki page states, this was never confirmed in any substantial way. More importantly, if development seized with no public comment, that would be one thing and may strengthen the "he got arrested" theory. However, there was some final communication, specific recommendations to rely on Bitlocker of all things, a new version of Truecrypt was relea…

I always believed that rather than publicly stating that they were about to be arrested or worse, which may alert regular, non-tech-savy people, he sent a hidden message in the arguably horrendous recommendation of replacing his tool with BitLocker.

I think he was trying to scream “Run!” without actually screaming “run”.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#245
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and…

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens.

Also “there is no appeal possible” should be plain illegal.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#247
post #115

Linux is the only hope at this point for the future of computing. Windows and macOS are just too risky to do any business with. Waste of all resources.

Don't worry, US states are working on making Linux illegal through age verification requirements in the OS.

[flagged]

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#248

Earlier quoted context omitted.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

Perhaps not legally, but technically, you have an option: don't use the Microsoft Store. This isn't as wild a suggestion as it may seem to non-Windows users: the store is barely used by Windows users. You can get your own code signing certificate from a public CA, sign your own installer, and post it on your website. This is still the primary way that Windows software is distributed. Microsoft does not have a hand in…

It’s become neigh impossible to get your own code signing cert these days. The 2025 update from the CA forum required code signing certs to be short lived (no more three or five year certs) and stored exclusively on an HSM. As a result, most companies cross-signing these certs have moved to a subscription PaaS model where you are issued a cert but never receive custody of it, and perform signing via their APIs, and are at their mercy should they decide to block your account.

Anyway, even if you could get your own cert it would be same thing: MS could revoke or blacklist your indicate cert (though usually the grounds for doing so are much less shaky than your account being suspended for vague “tos violations”)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#249

Earlier quoted context omitted.

Is this another example of their old modus operandi: https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis... ?

No. Embrace, Extend, Extinguish was replaced by the AAA strategy: Acquire, Assimilate, Abandon. They were trying to be more Google-like with that "Abandon" step I think. They've since moved on to the SSS strategy: Ship, Slip, Slop.

Good heavens! My acronymical notes on Microsoft's product strategy are two revisions out of date!

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#250
post #146
post #115

Linux is the only hope at this point for the future of computing. Windows and macOS are just too risky to do any business with. Waste of all resources.

and yet... still unusable by the mass majority of people.

This is always said by people who either never touch the Linux desktop, or exclusively use their own custom Arch setup.

You can install Fedora Linux, Linux Mint or Manjaro, and it's more user friendly than Windows 11 and macOS.

Post reply on HN