Live data from Hacker News

Microsoft terminates VeraCrypt account, halting Windows updates

404media.co

241–250 of 259 posts

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#241

Earlier quoted context omitted.

The distros are not pointless. For every one of them there was a human being that wanted something to work differently and the nature of open source let them do it. That should be celebrated and the day we loose that flexibility would be a very sad day.

This. Not to mention that for the mainstream users there are mainstream distros that are largely the same they have always been: Fedora, Ubuntu, Mint, so I never really understood the issue of having tons of distros out there for enthusiasts.

I think that both perspectives are right. We should celebrate diversity, but there's also power in consensus.

There needs to be some competition between ideas, but if every bit of disagreement about direction ends in "I'm going to build my own distro, with blackjack and hookers", then we as a community won't ever end up building something that can compete with the megacorps.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#242

Earlier quoted context omitted.

> a peer knows that a signature is valid because it can chain it back to a pre-established root of trust, rather than having to establish a new degree of trust in a previously unknown party. So the apt binary on your system comes with the public keys of the Debian packagers and then verifies that packages are signed by them, or by someone else whose keys you've chosen to add for a third party repository. They are the…

> What is obtained by further centralization? Nothing, I can’t think of a reason why you would want to centralize further. But that doesn’t mean it isn’t already centralized; the fact that every Debian ISO comes with the keyring baked into it demonstrates the value of centralization. > Each package manager uses its own independent root of trust. Yes, each is an independent PKI, each of which is independently centrali…

> Centralization doesn’t mean one authority

That literally is what centralization means:

> cen·tral·i·zation: the concentration of control of an activity or organization under a single authority.

I mean people try to motte and bailey this all the time. You have someone proposing or defending a monopoly by putting it up against the false dichotomy alternative where no party trusts any other party whatsoever and then everyone is required to do everything on their own because no delegation is possible.

There is an alternate which is neither of those things, and it's a competitive market. You have neither a single authority nor the total absence of trust. Instead there are numerous alternatives that each try to maintain a good reputation for themselves because people can choose freely among them without their choice being coerced by tying it to numerous otherwise-unrelated factors.

Notice how this is importantly different. If you have a PC, you can install Debian or Arch or Windows; if you install Debian, you can install software with apt or flatpak or snap; if you use apt, you can use the official repositories or numerous third party ones. If you have an iPhone, you get iOS and you get Apple's store and everything else is anti-competitively excluded.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#243
post #58

A year ago I used Azure Trusted Signing to codesign FOSS software that I distribute for Windows. It was the cheapest way to give away free software on that platform. A couple of months ago I needed to renew the certificate because it expired, and I ran into the same issue as the author here - verification failed, and they refused to accept any documentation I would give them. Very frustrating experience, especially s…

Azure is garbage at all levels

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#244
Hopefully this is just boot issues, and not VC in general moving forward for now. I just centralized on leveraging VC for container encryption. I actually moved away from VC back to Bitlocker for FDE just a couple weeks ago (I forget the exact reasons why)

But I still like it for containers, and I hope they can figure out a way to get it fixed for VC and WireGuard or they can figure out alternate signing options and a migration path.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#245

Earlier quoted context omitted.

This. Not to mention that for the mainstream users there are mainstream distros that are largely the same they have always been: Fedora, Ubuntu, Mint, so I never really understood the issue of having tons of distros out there for enthusiasts.

I think that both perspectives are right. We should celebrate diversity, but there's also power in consensus. There needs to be some competition between ideas, but if every bit of disagreement about direction ends in "I'm going to build my own distro, with blackjack and hookers", then we as a community won't ever end up building something that can compete with the megacorps.

This.

It takes leaders. And people with vision. It seems the lack is there, and not at technical makers.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#246
post #120

Earlier quoted context omitted.

> I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security For home/business users I'd agree. But in Embedded / money-handling then it's a life-saver and a really important technology.

Videogames are increasingly demanding secure boot.

A few competitive online games do, but most don't. That's why nowadays so many games run great on Linux.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#247

Earlier quoted context omitted.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the PRODUCER; id est provide guarantees to the PRODUCER that the firmware of the device they SELL has not been tampered with at some point in the PROFIT chain.

In my case a firmware provider went out of business, and in one particular device the firmware gets stuck in an endless boot loop. It tries to calibrate some led's, but forgets to round some differences, so it can never converge to a proper calibration.

Device is bricked, firmware is secured with a signing key, refactoring a new device is pretty hard. The current one needed 10 years of development. I'm on the wait to either patch the firmware by finding the problematic byte (if it's patchable, round() needs much more), or to wait for the original dev willing to release an update on his own. BTW Claude opus got much better than ghidra lately. It's perfect.

I see the value of protected firmware updates, but business has to survive also.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#248
post #126

Earlier quoted context omitted.

There is nothing stopping you from using third party certificates to sign Windows binaries. It's just expensive. You don't even need a MS toolchain or CLI tool for it.

> It's just expensive So yes there is.

Yeah but consider that if something is cheap or free (having Microsoft do it), what is the product? It's a tradeoff, pay for independence or be at the mercy of in this case Microsoft.

(there is probably a third, fourth, fifth option but this is an internet comment section)

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#249
post #229

Earlier quoted context omitted.

> It's just expensive So yes there is.

Having a fee that's trivial for serious software developers but too high for script kiddies shipping trash is a good thing.

But that's also a fee that's trivial for well funded criminal malicious parties shipping harmful trash but too high for serious open source developers shipping free software.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#250

Earlier quoted context omitted.

For what it’s worth, Trusted Signing verification has been a moving target over the last 12 months. It was open for individuals, then it was closed to anyone except (iirc) US businesses with DUNS numbers, then it opened again to US based individuals (and a few other countries perhaps). My completely uninformed guess was that someone had done something naughty with Trusted Signing-issued code signing certificates. Any…

I don't know anything about Trusted Signing verification, but I do know from reports on 'mini umbrella company fraud' that if you're a fraudster, there are people in the Philippines who will happily sign their name to western countries' official paperwork in exchange for $2000 or so. Understandably, as that's more than the country's median annual income. So I can see why offering trusted signing for individuals world…

Most RATs are signed, that's a hurdle but it's clearly not a big deal to bypass for criminals, many "SSL companies" provide them, just have to use fake docs and you'll be issued it, many shady services sell those signatures as well and it doesn't look like it cost more than $15 per binary, so obviously, not so secure in practice.
Post reply on HN