Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

281–290 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#281

Earlier quoted context omitted.

Surprised to see you here. Thanks for all your hard work. Windows users are in a tough spot, but with the dawn of Copilot, nobody should be surprised. Frankly, those who remain with Windows after this latest betrayal have chosen their fate.

> those who remain with Windows after this latest betrayal have chosen their fate. Ah. So almost every single business in the world… suckers?

Yes.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#282

Earlier quoted context omitted.

The other day I tried to create a Github account and was repeatedly told I am fraudulent. Nothing else. Try again later, it says. This is the same thing that's happened every time I've tried to have a Microsoft account. I don't think Microsoft wants to have customers who aren't rich.

Maybe some bot signed up using your email and then did bot things on it. I've had that happen a lot over the years. My Microsoft account is still stuck in German because that's the language the bot used when creating the account (to spam X-Box apparently).

I got a 20y old hotmail/live account deleted by Microsoft because a bot tried to reset my password too many times. Considering the magnitude of the targeted attack, MS found the safest way to keep me secure was to wipe my account. That way the attacker could not get into my account.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#283

Earlier quoted context omitted.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

Perhaps not legally, but technically, you have an option: don't use the Microsoft Store. This isn't as wild a suggestion as it may seem to non-Windows users: the store is barely used by Windows users. You can get your own code signing certificate from a public CA, sign your own installer, and post it on your website. This is still the primary way that Windows software is distributed. Microsoft does not have a hand in…

Thank you for that. Although it may be unlikely, I'd love to see a mass exodus away from their failed attempt to emulate all the worst aspects of appstores popularized in other platforms.

I grew up being able to download software and install it, and actually prefer that model (relying on reputational trust of the party publishing it, my own verification from other signals researched, or sandboxing techniques where appropriate).

Most users may not be aware, but a rare gem of a version of Windows that refreshingly doesn't even come with the store (or a bunch of the other unwanted bloat) is IoT Enterprise LTSC.

As a lifelong Windows user, the premise of Microsoft controlling what goes on my PC is revolting. I'm buying a tool from them, not a set of handcuffs. If it was some non-profit, open-source group running the store I might be more inclined to trust it. But ultimately the only gatekeeper on a product I own should be me. Otherwise I don't really own it, which leads to problems like this one.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#284

First I was surprised to read the Veracrypt maintainers could be in this situation, then read the top comment where Wireguard maintainers are too (unless I misunderstood). Is this some malicious new program inside Microsoft to try and shutdown open source projects so they can push Windows products and solutions more?

Yes.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#285

That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game…

Microsoft has been taking steps to mitigate the leaked code signing certificate problem.

On the driver side of things, new versions of Windows no longer trust the cross-signed certs, so you must submit your driver to Microsoft to validate and sign, so no private key to go missing. https://techcommunity.microsoft.com/blog/windows-itpro-blog/...

On the regular Authenticode side of things, the new CA/B Forum rules have prohibited storing new private keys outside of hardware modules for a while now, so eventually you won't be able to find a leaked private key for code signing that would still be valid.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#286
post #67

Earlier quoted context omitted.

the current law requires no verification at all simple attestation, you could put in _any_ age. it also does not effect linux distros as a whole, only distros in jurisdictions with the laws.

Sure, for now... I simply don't believe it will stop at "simple attestation", because we all know that simple attestation is practically useless, but once the various distros accept this "trivial" inconvenience, "Age verification 2" with harsher requirements will soon be on the way. I would be ecstatic to be proved wrong on this, but experience tells me that is not likely to happen.

We all know it's not about age, it's about user identity. As above, it's clearly a wedge so it's not rhetorical to observe more invasive and controlling features are coming.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#287
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

They sure do earn enough money to afford whatever number that is on your mind.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#288
post #81

Earlier quoted context omitted.

It's much worse than you think. Press coverage -> manual intervention is at best a bandaid covering up a major wound in a flaw that happens with independent software distribution. The old model where the user decides which software or apps to run on their machine, is basically already replaced by a whitelist system that is managed by companies who have no interest or obligation to approve developers. Factors like ”be…

Some countries (the EU in general) are already doing things about this. Owning the app store means you are a monopoly and now the only question is are you illegal by the local laws which vary. You can/should write your congressman (or whatever they are called in your country) and get better laws in place.

You are not wrong that regulation is desperately needed, and that EU is doing good things. However, even the EU which are doing the right thing on an anti-trust pro-competition basis, they fundamentally succumb to the same misconception – that middlemen are necessary at all. The EU doesn’t care about the App Store model, they care about the App Store monopoly. They are right about that, but the solution isn’t alternative app stores - it’s much simpler: the solution is NO App Store.

More specifically, it used to be feasible to distribute software between me (the developer) and my customers (the users) without a mandatory gate keeper that looks at me and decides whether I’m worthy, am from the right country, have good intentions etc. This is currently necessary on all desktop and mobile platforms except Linux. There is exactly 1 gatekeeper per platform (the platform owner who controls your device), except windows, which effectively have like 3-4 CAs that’s shrinking every year due to mergers and private equity ownership.

Software curation and reputation systems can be good, either with whitelists (say steam) or blacklists (say antivirus). I can see some use cases for it, but they should be within user control. What we have now is worse than a fearmongering Stallman rant. It’s incredibly bad, both pragmatically and philosophically.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#289

Earlier quoted context omitted.

1) its weird to disparage someone that is trying to help, no matter how small or large of an effect you think the help will have 2) they got 120,000 views, 400 retweets, and 1.7k likes in ~12 hours. that is a good amount of awareness. certainly more than i would get from a tweet. certainly more help than whatever you are doing here.

Their tweet was trying to help. Their comment here is bragging about how important they think they are.

>Their tweet was trying to help. Their comment here is bragging about how important they think they are.

ah, well thank god you came in here and set them straight.

i am sure the veracrypt maintainer is appreciative of your service.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#290
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and…

It always weird to see how dichotomy of some people saying AI will never be profitable and are doomed to fail and others saying that they are such a essential public service that they are a utility and should be subject to government regulation. Hopefully they are not the same group of people, but I suspect there is a greater overlap that one would expect.
Post reply on HN