Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

361–370 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#361
post #59

Earlier quoted context omitted.

Until Microsoft decides to no longer sign the Linux boot loader shim (for IBM/Red Hat, no less).

In most cases you can put your computer secure boot in setup mode and roll your own keys.

Until they making CA a requirement, then disable changing the CA settings and it defaults to Microsoft. Then you are fucked.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#362

Earlier quoted context omitted.

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and…

If it is regulated as a utility, the government will want to ban these hacking tools.

I think the GP is relating to MS services and accounts as utilities that should not be possible to be taken away easily, not about Wireguard.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#364
post #324
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

You said: "Currently undergoing some sort of 60 days appeals process, but who knows." .. and the op said: "I have tried to contact Microsoft through various channels but I have only received automated replies and bots. I was unable to reach a human." ... which is a roundabout way of saying you did not spend lawyer hours and you did not contact them through channels that they cannot ignore: registered, physical mail,…

No. The humans just said 60 days.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#365

Earlier quoted context omitted.

This has got very little to do with children - that is just the excuse that sounds good. "Think of the children" is a rhetorical tactic that anyone who wants to get unfettered access to your data rolls out whenever they can. It is a tactic that unreasonable people use to influence reasonable people, because it is so difficult for a reasonable person to argue against without coming across as uncaring and/or bigoted.

If it was an excuse to get your data there would be some data-getting involved. It may be hard for you to believe, but lots of people really do want parental controls that actually work and are bound by the force of law.

Yes that may be true, but parents are being misguided by efforts that are trying to control aspects of data.

If you, as a parent, make yourself open to this attack, you will find that you are making us less free of a society by expecting others to parent for you.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#366
post #164

https://community.osr.com/t/locked-out-of-microsoft-partner-... Could be a related issue to this? Maybe Microsoft just doesn’t want driver developers for whatever reason.

its my computer. its my os. i own it. I paid my money and bought the program. not them. I am free to install whatever software and modify whatever kernel components as i see fit. I am so sick and tired of the continued erosion of the ownership model. I dont want to rent anything. But corporations see it as an avenue to increase revenue. We pay more, for less. What else is new.

It’s time to switch to Linux or another open OS.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#368

Earlier quoted context omitted.

While I agree entirely that Linux in 2026 has never been more usable… how much actual work is being put into Office and 365 tooling native on Linux? Like none. Literally the best office you MIGHT KIND OF be able to run in 2016, but probably more like 2013. Valve focused on games, that is awesome and really helpful… But there are 10,000 distros and instead of putting real resources to put even rickety bridges over MS’…

> While I agree entirely that Linux in 2026 has never been more usable… how much actual work is being put into Office and 365 tooling native on Linux? Why the hell would you want that? Office365 is a buggy piece of nightmare.

Because even though you don’t like a thing, the entire world of business uses it.

Hold your nose and work on WINE if you need to think that way. But MS has moats, and office is one of the widest.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#369
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

Look how much profit Microsoft made last year.

"Financially, it was a year of record performance. Revenue was $281.7 billion, up 15 percent. Operating income grew 17 percent to $128.5 billion." https://www.microsoft.com/investor/reports/ar25/index.html

So don't be so naive to tell us that 1-2 additional people to handle the appeal process is anything but rounding error in their balance sheet.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#370

Earlier quoted context omitted.

It’s become neigh impossible to get your own code signing cert these days. The 2025 update from the CA forum required code signing certs to be short lived (no more three or five year certs) and stored exclusively on an HSM. As a result, most companies cross-signing these certs have moved to a subscription PaaS model where you are issued a cert but never receive custody of it, and perform signing via their APIs, and a…

I was afraid of the HSM at first but for an open source developer (rather than a big company) I found it wasn't a big deal. I can't sign in GitHub Actions and I have a USB stick that lights up when I sign releases, but it hasn't been a blocker. I got mine from Sectigo Store. This isn't hypothetical, I really did it, I've got the HSM, it works. It wasn't difficult. It just cost some money and a little bit of time. "Ni…

Thanks for sharing your experience. I have been code signing releases for over a decade as an indie publisher myself, until I found myself effectively iced out by the HSM requirement, the increased cost, and the shortened cert lifetimes, which, as someone with certain executive order dysfunctions, I already had a hard time being on top of with the old (multi-year) lifetimes.

I just migrated to MS artifact signing and, thank the lord, had an actually easier time getting verified than I did with the Sectigo and Comodo in the past. I’m sure I’m not representative of anyone else’s experience but having already had a developer account (with a different email and without an Azure account!) that I had already been using for the Microsoft Store might have helped, as well as the fact that I had a well-established business history (I’ve heard businesses younger than 3 years can’t get verified??), but reading all the comments here makes me very uneasy about the future.

It’s good to know the HSM route isn’t a complete non-starter. The main reason I panned it is that when I started looking into this I found that a number of companies that had previously offered the HSM route had done a bait and switch and were now keeping custody unless you were big enterprise (meaning willing to put up with 10k/yr fees). I did find a few that would allow OSS devs to sign their work, but read horror stories on Reddit and elsewhere about their freezing the account and issuing no refunds if you ask them to issue the cert in the name of your LLC or corporation instead of with your personal name (which I expressly did not want). Also, they actually were more expensive than Azure artifact signing even after the HSM cost was taken out.

Post reply on HN