Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

251–260 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#251

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

I suggest that developers could self-sign to verify the legitimacy of future updates. Otherwise leave it unsigned.

This entire "big tech overlords have to sign apps & drivers to keep you safe" concept is one giant pile of nonsense.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#252
post #16
post #6

They need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.

I blew the lid on X today: https://x.com/i/status/2041698657368703484

[flagged]

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#253
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and…

If it is regulated as a utility, the government will want to ban these hacking tools.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#254
post #99

Earlier quoted context omitted.

That seems like a very nonsensical stance.

Well look at something like ANOM. The FBI encouraged its use. Because it was run by the FBI and they could see all the private messages. If Veracrypt was a honeypot, the powers that be would go out of their way to make it as easy to use as possible. They'd instantly sack whoever made this decision, and reverse it.

So is coreutils a honeypot?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#255
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

"Never attribute to malice that which is adequately explained by stupidity"

When a company makes it impossible to correct their stupidity, it's a malicious act. The behavior speaks loud and clear: "We don't care what damage we do to developers or users. And we don't want to hear about it."

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#256
What sucks about this, is due to implementation,Windows is the only way to achieve some stuff in Veracrypt. For example: doing full system partition encryption, and the Hidden OS install that only Veracrypt can do- requires Windows with the computer set to MBR rather than UEFU. I had hoped we'd see more of the plausible deniability tech at the OS level

But aside from one or two experimental attempts, also presented at BlackHat https://web.archive.org/web/20250914062843/https://portswigg...

- the consumer has nearly lost access to high end plausible deniability

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#257
post #67

Earlier quoted context omitted.

Sure, for now... I simply don't believe it will stop at "simple attestation", because we all know that simple attestation is practically useless, but once the various distros accept this "trivial" inconvenience, "Age verification 2" with harsher requirements will soon be on the way. I would be ecstatic to be proved wrong on this, but experience tells me that is not likely to happen.

Simple attestation is very useful for the case where a parent gives a child access to a computer and wants that computer to block porn. That's the use case everyone is clamoring for, and asking the root user "how old is this user?" solves it in a simple, open, privacy-preserving way. Everybody wins, except the teenager who wants to watch porn. If this were not legally mandated, everyone would support it as a useful f…

This has got very little to do with children - that is just the excuse that sounds good. "Think of the children" is a rhetorical tactic that anyone who wants to get unfettered access to your data rolls out whenever they can. It is a tactic that unreasonable people use to influence reasonable people, because it is so difficult for a reasonable person to argue against without coming across as uncaring and/or bigoted.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#258
post #245

Earlier quoted context omitted.

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and…

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

In the EU, under GDPR, it is legally required to explain automated profiling.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#259
post #2

Microsoft disabled the developer's certificate so no windows releases can be made.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

According to this: https://x.com/EdgeSecurity/status/2041872931576299888

> ...it seems like they instituted an identity verification policy, didn't notify me about it, and then I guess they suspended accounts who didn't do the verification.

So, make sure you verify your account? Check spam folder regularly? Log in via web interface at least once a year?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#260
post #164

https://community.osr.com/t/locked-out-of-microsoft-partner-... Could be a related issue to this? Maybe Microsoft just doesn’t want driver developers for whatever reason.

Presumably it’s part of their commitment to kill kernel patching in Windows, to prevent another Worldwide Enterprise Windows Outage Caused By A Buggy Vendor DLL event.
Post reply on HN