Live data from Hacker News

Microsoft terminates VeraCrypt account, halting Windows updates

404media.co

251–259 of 259 posts

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#251

Earlier quoted context omitted.

Instead of proprietary SecureBoot controlled by megacorps, you can use TPM with Heads based entirely on FLOSS with a hardware key like Librem Key. Works for me and protects from the Evil Maid attack.

You can also use SB with your own keys (or even just hashes)...just because Microsoft is the default included with most commercially sold PCs—since most people use Windows on their PCs—doesn't mean SB is controlled by them. You can remove their signing cert entirely if you want. I have done this and used my own. Plus they signed the shim loader for Linux anyways so they almost immediately gave up any "control" they m…

Won't removing the Microsoft key prevent UEFI option ROMs from PCIe cards from loading when Secure Boot is enabled?

Is it even possible to install firmware containing an oprom resigned with a custom key onto, say, a modern Nvidia GPU, without the entire firmware bundle being signed by Nvidia's own key?

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#252

Earlier quoted context omitted.

> It's just expensive So yes there is.

Yeah but consider that if something is cheap or free (having Microsoft do it), what is the product? It's a tradeoff, pay for independence or be at the mercy of in this case Microsoft. (there is probably a third, fourth, fifth option but this is an internet comment section)

Yeah they're awful, I'm just saying making it harder for people to put apps on your OS might actually be a bad move. But sure, they can always scrape the barrel.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#253
post #223
post #103

Earlier quoted context omitted.

I like the idea of a central signing authority for open source. While this might go against the spirit of open source, I think it eventually creates a critical mass and outcry if Microsoft or Google would play games with them. Also foundations might be a good way to protect against legal trouble distributing OSS under different regulations. I am imagining e.g. an FDroid that plays Googles game. With reproducible or a…

> I like the idea of a central signing authority for open source. It would be the most corrupt(ible) org ever involved in open source and it would promote locked-down computing, as that would be their main reason to exist. Be careful what you wish for!

While agree that this is a problem if becoming an attack vector, FDoid does already do central signing of their own builds. With reproducible builds actually the attack vector would be minimal and actually maybe there could be multiple of such entities, which would make this even more robust. I just think the answer to power is not always decentralization. Alternatively government actors could also build open source for their citizens. Here would have at least democratically mandated corruption. IMHO this is much better than the current quasi government of the internet by a few powerful gatekeepers.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#254
post #253
post #223

Earlier quoted context omitted.

> I like the idea of a central signing authority for open source. It would be the most corrupt(ible) org ever involved in open source and it would promote locked-down computing, as that would be their main reason to exist. Be careful what you wish for!

While agree that this is a problem if becoming an attack vector, FDoid does already do central signing of their own builds. With reproducible builds actually the attack vector would be minimal and actually maybe there could be multiple of such entities, which would make this even more robust. I just think the answer to power is not always decentralization. Alternatively government actors could also build open source…

Then it wouldnt' be a central signing authority. Not that it matters. Several signing authorities would not equally divide the clients. One would emerge as central, become corrupted by industry commercial interests, promoted further by them, and end up some sort of Google of signing where you can't do anything on your computer without their knowledge and approval.

My second argument stands.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#255

Earlier quoted context omitted.

> What is obtained by further centralization? Nothing, I can’t think of a reason why you would want to centralize further. But that doesn’t mean it isn’t already centralized; the fact that every Debian ISO comes with the keyring baked into it demonstrates the value of centralization. > Each package manager uses its own independent root of trust. Yes, each is an independent PKI, each of which is independently centrali…

> Centralization doesn’t mean one authority That literally is what centralization means: > cen·tral·i·zation : the concentration of control of an activity or organization under a single authority. I mean people try to motte and bailey this all the time. You have someone proposing or defending a monopoly by putting it up against the false dichotomy alternative where no party trusts any other party whatsoever and then…

I think you way over-read this.

My point was that Debian, etc. as conceptually distinct organizations, and so there’s no point in centralizing beyond their organizational boundaries. Each already performs centralized key management, but nobody would particularly benefit from a single global keyring for all Linux distributions, because nobody (?) is transferring package formats across distribution families.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#256

Earlier quoted context omitted.

Its a simple solution in law to enable. Force manufacturers to allow owners of computer to put any signing key in the BIOS. We need this law. Once we have this law, consumers csn get maximum benefit of secure boot withiut losing contorl

But that's how it already works. If you install Windows first, Microsoft takes control (but it graciously allows Linux distros to use their key). If you install Linux first, you take control. It's perfectly possible for you to maintain your own fully-secure trust chain, including a TPM setup which E.G. lets you keep a 4-digit pin while keeping your system secure against brute force attacks. You can't do that with the…

Not really. There are many laptops where you cannot rrally get rid of Microsoft key and also cannot put your own key.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#257

Earlier quoted context omitted.

Its a simple solution in law to enable. Force manufacturers to allow owners of computer to put any signing key in the BIOS. We need this law. Once we have this law, consumers csn get maximum benefit of secure boot withiut losing contorl

> Its a simple solution in law to enable. Force manufacturers to allow owners of computer to put any signing key in the BIOS. ...it's already allowed. The problem is that this isn't the default, but opt in that you need quite a lot of knowledge to set up

I have set it up on worst laptops. There are laptops like hp x360 which doesn't allow modification at all.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#258
post #176

Earlier quoted context omitted.

Funnily enough, when you buy a house, the first task is to change all the locks. Y’know, for security.

Sure. Now, of the people who buy houses -- how many of them would find this a difficult or onerous task? And then, do computers . Apples and oranges here, for this point.

Cost me $500 recently. Not difficult, but costly.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#259
post #137

Earlier quoted context omitted.

You expect that stuff to happy with 3 letter agencies.

Sorry, I have no idea what you are trying to say.

Happens with 3letter agencies like NSA and CIA which keep close tabs on current and former employees.
Post reply on HN