Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

31–40 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#32

Looks like Linux and some of the BSDs are the only remaining truly open OSes.

True, however, that has been the case for quite a while. This particular incident doesn't change that, except for the VeraCrypt developer, who is in a crappy situation now (not just regarding VeraCrypt, he mentions he was using the certificate for his main job as well, so this sucks a lot for him).

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#33

It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.

Probably not French though, give how hostile it appears to be to encryption/security related projects (GrapheneOS had a good arguments re: that)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#35

It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.

Yeah but isn't the point of these certificates to express trust?

The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit.

Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a CA and as an organization.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#36
maybe an old vulnerable signed driver can be used to load the new version :D. on a more seirous note, i think contact with a person at MS, likely via socials triggering that, might help here. It all depends on the reason for the ban/block/cancel.

if they had a reason other than 'oops mistake' its likely just going to remain in place. (sadly, that is how MS is. if you care for privacy maybe go to BSD)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#37
post #2

Microsoft disabled the developer's certificate so no windows releases can be made.

We can still install, right? It just comes up with a scary warning. Still not great but at least we aren't locked out.

You can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#39
This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't freak out!) In that case, Microsoft would have my hands entirely tied.

If anybody within Microsoft is able to do something, please contact me -- jason at zx2c4 dot com.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#40
post #4

It's like LibreOffice all over again: https://www.neowin.net/news/microsoft-bans-libreoffice-devel...

This is worrying on many levels. So Microsoft force you to create an account to use Windows and then they reserve the right to block you from your own account, thereby potentially making you lose access to all your OWN data. This is crazy and yet another reason to stop using Windows as soon as possible.
Post reply on HN