Live data from Hacker News

Microsoft no longer signs Windows drivers for Process Hacker

borncity.com

281–290 of 543 posts

Re: Microsoft no longer signs Windows drivers for Process Hacker

#281

Earlier quoted context omitted.

But even if you can somehow make your own hardware, how long until governments start requiring interaction with certain services (health, banking, taxes, etc) be signed by an _approved_ OS/processor combo? Imagine tax software (comercial or gov provided) refusing to work unless you use an OS with TPM support for "security reasons". Or even worse, what would happen if gov regulations started requiring ISPs to stop wor…

> Imagine tax software (comercial or gov provided) refusing to work unless you use an OS with TPM support for "security reasons". > I don't think this will happen any time soon (hopefully) but I can see how even making your own hardware might no be enough. This already happened in Android, at least where I lives (Indonesia). Most of Banks, Government Services, and freaking McDonald's apps will refuse to run if your p…

Honest question: how do those apps know your phone is rooted, and can you still use their websites for equivalent functionality?

Re: Microsoft no longer signs Windows drivers for Process Hacker

#282
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

Back to the Mac for me. Yeah, they have the walled garden problem too, but *nix environment for my development hobby is better there than I have on Windows 10. I’m not willing to go all the way to Linux for my main system since my wife has to be able to use it. Numerically developer desktops aren’t significant, but mindshare is.

Apple are doing exactly the same thing. I'd even say they're slightly ahead of Microsoft on the storification of their desktop OS.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#283
post #221

Earlier quoted context omitted.

They've always been acting as a strong monopolistic corporation with a "fuck you" attitude. Here's a summary of Microsoft attitude these part 5 years: - rebrand as open-source friendly, only open-source whatever narrow side-projects they barely care about but could be run on other systems (VSCode, Powershell); distribute official packages with spyware - monopolize the education system by offering bribes including gra…

Note that secureboot does have a minor advantage for encryption at rest. Making much weaker passwords acceptable. I am happy my work laptop has secureboot. And I get why they lock down their device for me to use. For devices I own, I gotta control the secure boot, or I simply don't own it.

In theory, yes. In practice, what control do you have over the hardware? Can't basically anyone with a few million dollars to throw at the problem compromise any form of Secure Boot? If you're NSA, no need to go so far... they've probably got access to the Microsoft root signing key.

If the schematics and code to the TPM were free and there were "tamper evidence" mechanisms in place, we could argue secure boot had some benefits for security. But in its current forms, it's just preventing users from owning their devices with little evidence for security for determined attackers.

Machines should be simpler and auditable: that's how reliable security works. Adding piles of shit on top the other piles of shit is just producing more overall shit.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#284
post #214

Earlier quoted context omitted.

What about the scenario where your laptop is stolen and the attacker reads your data off the disk? All modern mobile devices protect against this scenario by default, but Windows devices required additional configuration to be protected. And in fact Secure Boot does protect against Grandma being infected by boot-time malware. And when has it ever been the case that it prevented you from installing Linux?

>And in fact Secure Boot does protect against Grandma being infected by boot-time malware. And how can grandma get boot time malware at Home? IIRC those were common back in the days when people were plugging in infected floppy disks or thumb drives everywhere and you'd try to boot off them. Can't remember last time I saw this type of malware in the wild as phishing and ransomware is a lot more profitable for maliciou…

> This was always the case ever since secure boot launched and any OS that didn't have it's first stage bootloader signed by Microsoft could not boot. Even To this day, to install arch or puppy on my XPS i had to disable secure boot. Ubuntu and other major distros are fine here though but this gate keeping doesn't make it ok in my book.

But this is kind of a circular problem, isn't it?

If everyone's bootloader is signed and recognized by every Secure Boot implementation, then signing is useless since it doesn't afford discrimination between "known good" and "dubious" bootloaders.

I'm not familiar with XPS computers, but to me what's important, as another sibling says, is that the user be able to load their custom keys with which they sign their own bootloader. This is how I run Arch on my HP computers.

This way, I can be reasonably sure that when I boot my arch linux, it's actually mine, and not some random live medium based of arch's (or whoever's) install disk that will sniff my passwords or whatever.

To me, this is what SecureBoot is supposed to offer, and I don't see how you would implement this if you could easily get anything signed and accepted by most PCs.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#285

Earlier quoted context omitted.

I find it interesting that, one one hand they are implementing features "in the name of security" that limit the owner of a computer what he/she can do with it and on the other hand they are adding backdoors so that government agencies (or anyone with right information) can spy on citizen that use this "secure" OS.

I will personally pay you twenty thousand US dollars (in the cryptocurrency of your choice, bank transfer, western union, whatever) if you can prove beyond reasonable doubt that Microsoft has ever secretly shipped a backdoor in their OS so government agencies could spy on their users. Perhaps you will be the first person to actually prove the existence of the NSAKEY backdoor? (I doubt it.)

[deleted]

Re: Microsoft no longer signs Windows drivers for Process Hacker

#286

Earlier quoted context omitted.

I find it interesting that, one one hand they are implementing features "in the name of security" that limit the owner of a computer what he/she can do with it and on the other hand they are adding backdoors so that government agencies (or anyone with right information) can spy on citizen that use this "secure" OS.

I will personally pay you twenty thousand US dollars (in the cryptocurrency of your choice, bank transfer, western union, whatever) if you can prove beyond reasonable doubt that Microsoft has ever secretly shipped a backdoor in their OS so government agencies could spy on their users. Perhaps you will be the first person to actually prove the existence of the NSAKEY backdoor? (I doubt it.)

[deleted]

Re: Microsoft no longer signs Windows drivers for Process Hacker

#287
post #25

In related news - ever wondered why Windows 11 can't be installed on "older computers"? You know, the ones that don't have a TPM chip? Now you know. Windows 11 completes the lock-up of the OS. That's why Windows 11 exists in the first place. All other changes are secondary. Microsoft knows they would've not been able to pull shit like this as a Windows 10 update, so they were effectively forced to do a version increa…

Back to the Mac for me. Yeah, they have the walled garden problem too, but *nix environment for my development hobby is better there than I have on Windows 10. I’m not willing to go all the way to Linux for my main system since my wife has to be able to use it. Numerically developer desktops aren’t significant, but mindshare is.

> I’m not willing to go all the way to Linux for my main system since my wife has to be able to use it.

What is the problem with using it? My non-technical relatives are quite happy with their Debian which I installed for them.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#288
post #271

Earlier quoted context omitted.

I'm not the person you were replying to, but here's the straw that broke this multilingual camel's back: unless Gnome is running under Wayland, switching the keyboard layout steals the input focus away from the foreground window briefly, causing focus-loss event handlers to fire. This might seem an easily fixable minor issue but it's actually a decade-old hairball which significantly harms the experience and can't be…

I don't recall this ever happening to me in KDE under X, at least not in a way I've noticed.

It's a Gnome-specific thing

Re: Microsoft no longer signs Windows drivers for Process Hacker

#289

Earlier quoted context omitted.

I saw the writing on the wall the moment they could sloppily justify the TPM requirement. Then I got into arguments with people proclaiming that it's just Microsoft enforcing it for the casual user's safety, and that I'm a Microsoft hater. Who? Me, whose first programming language was C#, who worked as an Windows server administrator for years, and my operating systems have been nothing than Windows for 2 decades. An…

The issue isn't the TPM, it's who owns the keys to the machine. If the user configures their own keys, it becomes an empowering technology that allows them to verify their boot process hasn't been tampered with. If Microsoft owns the keys, they own the computer and the technology becomes their means of control over the user. They will use this technology to oppressively deny the user their software freedom while simu…

Insightful analysis, though "oppressively deny" sounds harsh to me. There is not a blatant malice in TCG per se, mainly a neutral desire for control and by proxy profit. The treacherous versus trusted computing debate really does boil down to control. Do we trust vendors to be stewards of control on our platforms? Do we even have a choice?

I do not recall giving the keys to anyone, and yet it feels like the person building your house is telling you that they can pop in for dinner and lock you out should the need arise (deny you the ability to run your choice of software and your control is forfeit).

There is something flagrant when the question is brought home to the personal computer. No user complains too much about not being able to replace the firmware for some faraway BGP router, yet that router is also part of the infrastructure like the PC and the OS installed on it. If a consumer thinks about the PC less as providing a personal computing service and more as an Internet terminal, then the problem goes away a little. Naturally, the PC does both, but since the two are at odds with one another, the PC has conflicting interests, serving two masters.

A similar issue exists with cell phone debug, where the carriers log into your phone to troubleshoot. Granted, debug is control for the sake of helping the user and does not deny the user the ability to run software (the OS and app store do that).

This just leaves the problem of where can a user actually go to do secure compute. An abacus works nicely, but is impractical. Free open source hardware (FOSH) is really the only option.

Re: Microsoft no longer signs Windows drivers for Process Hacker

#290

Earlier quoted context omitted.

Not without massive loss of users. Both Microsoft and Apple would love to lock down their platforms, but they have to do it in tandem or users will flock to the other. So we will see a slow lock-in creep until they look like current day smartphones. Only way to stop this is to react strongly, so if most users are apathetic like you then it is inevitable. Of course I believe that you are right and most are this apathe…

>So we will see a slow lock-in creep until they look like current day smartphones. So we will see the rise on Linux on the desktop.

...and on smartphones.
Post reply on HN