Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

311–320 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#311

First I was surprised to read the Veracrypt maintainers could be in this situation, then read the top comment where Wireguard maintainers are too (unless I misunderstood). Is this some malicious new program inside Microsoft to try and shutdown open source projects so they can push Windows products and solutions more?

It feels more like an automated block due to uncharacteristical increase in download activity. Something that it seems more and more companies are taking seriously is the cottage industry of scams involving less technically savvy downloading apps online and getting their information stolen. The motivation for this is probably the same as Google stopping side loading. Take that as you want.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#312

Earlier quoted context omitted.

As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?

According to this: https://x.com/EdgeSecurity/status/2041872931576299888 > ...it seems like they instituted an identity verification policy, didn't notify me about it, and then I guess they suspended accounts who didn't do the verification. So, make sure you verify your account? Check spam folder regularly? Log in via web interface at least once a year?

> So, make sure you verify your account?

What ? On my computer ? Microsoft really has some nerves. My Microsoft account is scheduled for deletion.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#313

Earlier quoted context omitted.

Isn't this Microsoft abusing their quasi-monopoly as a consumer PC OS vendor? If it weren't for the current administration, I'd say it's time for regulatory action.

> If it weren't for the current administration Because the Democrats were better at keeping them on a leash? No. Clinton was in charge 30 years ago and blew it.

It was the Clinton administration that started regulatory proceedings against Microsoft, but it was GW Bush that was president during the conclusion of the case. And, true to form:

> The Department of Justice, now under Bush administration attorney general John Ashcroft, announced on September 6, 2001, that it was no longer seeking to break up Microsoft and would instead seek a lesser antitrust penalty

https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor...

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#314
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

I don't think they would be so much more expensive but they would be less profitable for sure and perhaps less "innovative" as a big chunk of the profit will go into regulation stuff.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#315
post #48

Looks like Linux and some of the BSDs are the only remaining truly open OSes.

Except compulsory age verification in Linux is now becoming a real threat. Some Linux distros are actively against this but many are not seemingly interested in fighting it: CachyOS, Ubuntu, Fedora and others. Age Verification is the thin end of a much bigger wedge in "open" OS's

Yes time to wake up.

I really believe most "open source" big projects have been compromised long ago. We have saw all those "Foundations" taking them over with all their governance, bureaucracy and goal which do not make any sense at the first look.

One example is Fedora, which is part of "The Digital Public Goods Alliance" [0], "a multi-stakeholder initiative that accelerates the attainment of the Sustainable Development Goals by facilitating the discovery, development, use of, and investment in digital public goods."

The Digital Public Goods Alliance has about every governments as member plus all the usual suspects: Gate Foundation and co.

All the leaderships have usually no background or experience in open source or even computers but are just magically placed there. But you can't say anything because they are mostly women.

You read the goals and roadmaps of those foundations and find out it has nothing to do with software or open source. It is basically there to control those projects and then have them implement all the age verification, digital id, etc.

So yes this is not a surprise all those projects are now all in absurd features such as age verification.

- [0] https://www.digitalpublicgoods.net/

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#316
post #43
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

It is more likely that government doesn't want to allow people to have privacy. Microsoft just obediently listen to orders and execute them.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#317

Earlier quoted context omitted.

EU is currently on its way to introduce mandatory age verification everywhere.

If I understand them correctly, the proposals are quite different. The US is effectively requiring the implementation of a third party verification service at computer set-up. The EUs approach validates an existing cryptographic identity that says you are over a certain age, without exposing your identification. Please correct me if I am wrong, this is what I read here.

Do you expect the EU to insist on a different solution once the US solution is in-place in all US-based operating systems?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#318
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

"Never attribute to malice that which is adequately explained by stupidity"

The guise of a harmless mistake has worn so thin and is so overused by tech companies that I now only see deliberate intent.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#319

Earlier quoted context omitted.

> Microsoft doesn't want to allow software that would allow the user to shield themselves I don't think Microsoft cares (about anything besides making mo' money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. No tinfoil needed.

>I don't think Microsoft cares (about anything else than making money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. Microsoft the corporation may only care about making money, but a lot of very high ranking folks within MS Security aren't just friendly to intelligence agencies, they take genuine pride in helping intelligence agencies. They'…

That's my experience with most computer security folks as well, and tech companies who sell security products. Cloak-and-dagger stuff running 24x7 in their heads.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#320
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

These are usually multi billion dollar companies, they’ll be fine, stop worrying about them.

Start worrying about the erosion of your rights as a consumer.

Post reply on HN