Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

321–330 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#321
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

> I understand the sentiment, but.. do you realize how much more expensive that would make all these services?

It wouldn't. For example, before Gmail, email was often free or nearly free (bundled with your internet service), but in most cases, you could talk to a human if you had issues with the service.

What we couldn't do is turn these business models into planetary-scale behemoths that rake in hundreds of billions of dollars in revenue. In essence, you couldn't have Google or Facebook with good customer support. I'm not here to argue that Google or Facebook are a net negative, but the trade-offs here are different from what you describe.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#322
post #42

Sorry to hear about this turn of events, but it was pretty much to be expected given the way the world is turning, and Microsoft being Microsoft. Switch to Linux if you can, and come give Shufflecake a try ;) https://shufflecake.net/

.... This deserves it's own posts , on HN, just for awareness-

Aside from https://web.archive.org/web/20250914062843/https://portswigg... , there haven't been really many goes at going for plausible deniability with modern systems, and I see the segment about a Hidden OS feature in work as well.

Hoping this succeeds. Funny, eventually Shufflecake, after it gets fully capable on Linux, might have to look at making versions for Windows and Mac

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#323
post #258

Earlier quoted context omitted.

In the EU, under GDPR, it is legally required to explain automated profiling.

How's that work? Got a link handy to explain to a dummy?

Article 13(2)(f)

"In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing: the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject."

EDPB Guidelines on automated decision making: https://ec.europa.eu/newsroom/article29/items/612053 especially page 25 is relevant

C‑634/21 is also somewhat relevant to understand how courts have applied ADM in general context of credit reporting https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... though it didn't specify what information actually needs to provided for 13(2)(f).

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#324
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

You said:

"Currently undergoing some sort of 60 days appeals process, but who knows."

.. and the op said:

"I have tried to contact Microsoft through various channels but I have only received automated replies and bots. I was unable to reach a human."

... which is a roundabout way of saying you did not spend lawyer hours and you did not contact them through channels that they cannot ignore: registered, physical mail, from a lawyer.

I'm sorry for these difficulties, truly, but don't tell me you can't reach a human when you most definitely can reach a human. From my own experience with an organization at least as calloused and indifferent as MS[1], as soon as I sent a real, legal communication I had real live humans lining up to talk to me.

[1] Pacific Gas and Electric

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#325
post #15

Earlier quoted context omitted.

It wasn’t always scummy… but there was a definite shift after they got bought. It’s kept getting worse since then. Then again, this was something like 20 years ago. Back then, Sourceforge was something closer to GitHub today. It was the de facto public source repository. You could even get an on-premise version, IIRC. Actually, this is sounding a lot like GitHub these days… not sure what that means.

As I've said elsewhere, freshmeat.net was better :-)

For project discovery, definitely -- but not as a source code repository.

Wow, we're dating ourselves on this, but I remember when it was a big deal that SF.net added SVN support. They apparently didn't turn off CVS until 2017!

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#326
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

Honestly, it's not our problem. Once a service becomes so vital it cannot be terminated without any meaningful process. My meta developer account is suspended and none of my appeals are responded to . Who can I talk to? Nobody. It's wrong.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#327
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Will send some emails.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#328
post #312

Earlier quoted context omitted.

According to this: https://x.com/EdgeSecurity/status/2041872931576299888 > ...it seems like they instituted an identity verification policy, didn't notify me about it, and then I guess they suspended accounts who didn't do the verification. So, make sure you verify your account? Check spam folder regularly? Log in via web interface at least once a year?

> So, make sure you verify your account? What ? On my computer ? Microsoft really has some nerves. My Microsoft account is scheduled for deletion.

I guess we can assume you won't be releasing any software for Windows in the near future :)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#329
post #115

Linux is the only hope at this point for the future of computing. Windows and macOS are just too risky to do any business with. Waste of all resources.

Don't worry, US states are working on making Linux illegal through age verification requirements in the OS.

Isn't linux complaint because of the systemd change?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#330

Earlier quoted context omitted.

Maybe some bot signed up using your email and then did bot things on it. I've had that happen a lot over the years. My Microsoft account is still stuck in German because that's the language the bot used when creating the account (to spam X-Box apparently).

I got a 20y old hotmail/live account deleted by Microsoft because a bot tried to reset my password too many times. Considering the magnitude of the targeted attack, MS found the safest way to keep me secure was to wipe my account. That way the attacker could not get into my account.

I had something similar with a 6-letter apple account that has never been compromised but I guess got put on some kind of list, because I had to go through account recovery almost every time I logged in, which wasn't a big deal until I got an iphone. Apple support was completely useless. Random old buried forum post in a stall marked "beware the leopard" mentioned the behavior and suggested changing the account name.

Nothing in the Apple site or phone stuff would even clue the user in to what was happening, much less how to resolve it.

Post reply on HN