Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

341–350 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#341
post #120

I would not be surprised if it was some sort of AI driven mistake. Some guy somewhere deciding to delegate threat assessment to Copilot or some other automated tool.

i would bet a years salaray that you are correct. copilot or some automated process. and then the message is automated with an automated appeal-denial flow.

conspiracy theories are fun and all, but 99.99% of the time it is just incompetence, miscommunication, etc.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#342
post #167

Earlier quoted context omitted.

I know it's not what people want to hear but my response to a lot of the comments here is just a general, I agree, it's time to stop using Windows. They won't let you secure your drive the way you want. They won't let you secure your network the way you want (per the top-level comment about Wireguard). In so doing they are demonstrating not just that they can stop you from running these particular programs but that t…

Stop supporting Windows as well. Open source developers are doing Microsoft a big favor when they support Windows and publish Windows builds and installers. It's a substantial effort, and apparently that effort isn't appreciated. If all open source software dropped support for Windows, it wouldn't really affect the open source community that much. It would definitely cause headaches for Microsoft however.

It's not that easy.

I agree that supporting Windows helps its ecosystem.

But also open source software on Windows is an important gateway to the free world. When you are already used to Firefox, LibreOffice and VLC, you might as well switch to Linux painlessly, but if those didn't run on Windows, switching to Linux would require relearning everything.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#343

Earlier quoted context omitted.

Perhaps not legally, but technically, you have an option: don't use the Microsoft Store. This isn't as wild a suggestion as it may seem to non-Windows users: the store is barely used by Windows users. You can get your own code signing certificate from a public CA, sign your own installer, and post it on your website. This is still the primary way that Windows software is distributed. Microsoft does not have a hand in…

It’s become neigh impossible to get your own code signing cert these days. The 2025 update from the CA forum required code signing certs to be short lived (no more three or five year certs) and stored exclusively on an HSM. As a result, most companies cross-signing these certs have moved to a subscription PaaS model where you are issued a cert but never receive custody of it, and perform signing via their APIs, and a…

I was afraid of the HSM at first but for an open source developer (rather than a big company) I found it wasn't a big deal. I can't sign in GitHub Actions and I have a USB stick that lights up when I sign releases, but it hasn't been a blocker. I got mine from Sectigo Store. This isn't hypothetical, I really did it, I've got the HSM, it works. It wasn't difficult. It just cost some money and a little bit of time. "Nigh impossible" is a tremendous exaggeration. I'll concede "annoying and expensive" perhaps. If you've got the money, you can get the HSM. You don't have to re-buy the HSM when you renew your certificate.

The Microsoft Store account was painful to set up, I'll note. My developer account had also been cancelled by Microsoft for unknown reasons, and I ultimately had to set up a brand new one. New email, new name. My new account has my middle initial because I couldn't clash with the existing, closed account. My first and last name alone are banished forever from the store.

The "same thing", as you concede, isn't the same thing. Quantity has a quality of its own: one happens all the time and we're reading an article about it happening right now. In the comments there's another prominent maintainer who it happened to, and it happened to me personally! That's three right here! The other happens so infrequently that people in this same HN thread are complaining that it isn't happening enough. Can you find an example that's like Veracrypt and WireGuard? In practice, it seems they rarely do this, even when they should. You can actually view the list under "Manage computer certificates" > "Untrusted Certificates." On my computer the entire list is 20 certificates.

I'm standing by my suggestion, 100%. These aren't equivalent risks at all.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#344
post #329

Earlier quoted context omitted.

Don't worry, US states are working on making Linux illegal through age verification requirements in the OS.

Isn't linux complaint because of the systemd change?

The only thing that systemd did was add a space and api to store an attested birth date. That is what the entire meltdown was about. A CRUD API.

Everything else about complying with the wacko age verification law is up to distro builders.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#345

Earlier quoted context omitted.

Simple attestation is very useful for the case where a parent gives a child access to a computer and wants that computer to block porn. That's the use case everyone is clamoring for, and asking the root user "how old is this user?" solves it in a simple, open, privacy-preserving way. Everybody wins, except the teenager who wants to watch porn. If this were not legally mandated, everyone would support it as a useful f…

This has got very little to do with children - that is just the excuse that sounds good. "Think of the children" is a rhetorical tactic that anyone who wants to get unfettered access to your data rolls out whenever they can. It is a tactic that unreasonable people use to influence reasonable people, because it is so difficult for a reasonable person to argue against without coming across as uncaring and/or bigoted.

If it was an excuse to get your data there would be some data-getting involved. It may be hard for you to believe, but lots of people really do want parental controls that actually work and are bound by the force of law.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#346
post #167
post #40

Earlier quoted context omitted.

This is worrying on many levels. So Microsoft force you to create an account to use Windows and then they reserve the right to block you from your own account, thereby potentially making you lose access to all your OWN data. This is crazy and yet another reason to stop using Windows as soon as possible.

I know it's not what people want to hear but my response to a lot of the comments here is just a general, I agree, it's time to stop using Windows. They won't let you secure your drive the way you want. They won't let you secure your network the way you want (per the top-level comment about Wireguard). In so doing they are demonstrating not just that they can stop you from running these particular programs but that t…

I think they've been heading that way for a while, and it's only getting clearer.

I've been thinking, and said before, 90s Microsoft was far from perfect, but they at least seemed to care a lot about the quality of Windows. 2020s Microsoft seems to see Windows users as a captive audience they can exploit for whatever the corporate executives fancy at the moment. It seems more like a gradual transition.

In any case, it seems to be getting more clear that Linux is destined to be the best OS for power-users.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#347
post #105
post #95

Earlier quoted context omitted.

It's more or less commonly accepted that its creator got jailed for being an arms dealer. https://en.wikipedia.org/wiki/Paul_Le_Roux

I knew the speculation on him being involved in some capacity, but as the wiki page states, this was never confirmed in any substantial way. More importantly, if development seized with no public comment, that would be one thing and may strengthen the "he got arrested" theory. However, there was some final communication, specific recommendations to rely on Bitlocker of all things, a new version of Truecrypt was relea…

Wasn’t there something with 7.1A and that the canary was gone after that version too?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#348
post #140
post #127

Earlier quoted context omitted.

I went on a Wikipedia dive and discovered this funny bit regarding the court process surrounding Lavabit and FBI's desire of the TLS private keys. > The contempt of court was caused by Levison providing the keys printed in a tiny (4 point) font, which was deemed "largely illegible" by an FBI motion, which went on to complain that "To make use of these keys, the FBI would have to manually input all 2560 characters, an…

> The court ordered Levison to be fined $5,000 a day beginning 6 August until he handed over electronic copies of the keys. Two days later Levison handed over the keys hours after he shuttered Lavabit.

I remember that. That was around the time they were using the National Security Letter to make things happen that were clearly illegal. Now look at where we are at. They are using Nation Security reasoning for anything.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#349
post #95
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

It's more or less commonly accepted that its creator got jailed for being an arms dealer. https://en.wikipedia.org/wiki/Paul_Le_Roux

> He subsequently admitted to arranging or participating in seven murders, carried out as part of an extensive illegal business empire.

Yikes

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#350
post #264

Earlier quoted context omitted.

I guess it means that even when something is (arguably) objectively more simple, people still won't bdge just because they don't want change. They don't want to learn new things. I myself am quite different. I have thoroughly had it with my current iPhone and am eyeballing /e/OS, before that I really started to find Android boring, before that Windows mobile (the nice one with the cards). I switch Gnome, KDE, some ot…

No, it means that people have requirements that Linux does not fulfill. I need the Office suite, and would rather not gamble with the various compatibility promises made by alternatives.

Good luck with that.
Post reply on HN