Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

371–380 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#371

Earlier quoted context omitted.

Surprised to see you here. Thanks for all your hard work. Windows users are in a tough spot, but with the dawn of Copilot, nobody should be surprised. Frankly, those who remain with Windows after this latest betrayal have chosen their fate.

> those who remain with Windows after this latest betrayal have chosen their fate. Ah. So almost every single business in the world… suckers?

are you making an argument that businesses worldwide somehow are known to make well thought-out, rational, wise decisions that are in best interest for the business and efficiency of running it?

because most managers I know in my professional life go with the vendor that buys them dinner or slips them tickets for box seats.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#372

Earlier quoted context omitted.

>I don't think Microsoft cares (about anything else than making money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. Microsoft the corporation may only care about making money, but a lot of very high ranking folks within MS Security aren't just friendly to intelligence agencies, they take genuine pride in helping intelligence agencies. They'…

I can completely believe this. I was always convinced that Skype was bought by microsoft so CIA/US intelligence agencies to have listening capabilities. The first thing Microsoft did after the Skype purchase was making it easier to tap into the calls by removing p2p calling and routing calls using centralized servers.

Yeah. Otherwise Microsoft purchasing Skype made no sense.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#373

Earlier quoted context omitted.

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

It's got a lot of analogy to restaurants banning Uber delivery for not handling their food to their standards.

That actually is not analogy at all and it makes sense. When a low-paid Uber Eats delivery person just throws the box carelessly and brings damaged dish to the customer, that's a real issue.

In digital services there's no such thing. There's only a damned corporation employing idiots who don't care about community.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#374
post #226

Earlier quoted context omitted.

Three lines of text in 12-point font in the corner which can be covered by a window is hardly “the entire screen.”

They changed it recently. https://learn-attachment.microsoft.com/api/attachments/f8eac...

Not the OP you responded too, but what the hell! I have not really used windows in a while but that's absurd. That text is massive just for an unsigned driver.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#375
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

With these big players who are regularly found supporting people with evil intentions: Don't attribute to incompitence what could be ascribed to malice, nay you must trust the gods of the clouds to keep your secrets for you, all for the low low price of $x.99 a month a seat, you may only cancel your service with an arcaine dance and the sacrifice of your first born!

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#376

If you use Veracrypt on Windows then you have no idea what you are doing. Windows is not safe. Use Linux only.

I would love to switch long time ago, but I make money on Windows enterprise customers, using specific Windows tools that have no reasonable Linux counterparts.

I'll throw my Windows laptop out of a (pun intended) window on the exact second I'll secure viable and sustainable income using Linux. I know it can be done, but so far it's outside of my circles.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#377

Earlier quoted context omitted.

>I don't think Microsoft cares (about anything else than making money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. Microsoft the corporation may only care about making money, but a lot of very high ranking folks within MS Security aren't just friendly to intelligence agencies, they take genuine pride in helping intelligence agencies. They'…

That's my experience with most computer security folks as well, and tech companies who sell security products. Cloak-and-dagger stuff running 24x7 in their heads.

There are quite a few extremely talented security folks who are more or less the polar opposite, who view people like Edward Snowden and Julian Assange as heroes, the NSA as guilty of treason, as James Clapper as guilty of perjury, even inside of corporations like Microsoft.

The catch is, views like those must be kept to a fairly modest level by the people who hold them. Discussing them with ideologically aligned colleagues may be fine, but for example, when someone makes statements or asks questions with such pro-privacy framing on stage directly to security leadership at internal company conferences, that is a quick way to a severance package not only for the person on stage, but also for dozens of folks in the audience who clapped a little too enthusiastically at the onstage remarks.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#378

Earlier quoted context omitted.

Linux is stuck because it's made and maintained by people who love linux. Look at popular unix based OS's - Android, MacOS, iOS.. Whats the first thing they do? Take the command line out back and shoot it. Whereas for linux users, their is this l33t h4cker festishization of only using a keyboard to do everything. All these distros have an extremely robust CLI under the hood, and an afterthought quasi GUI on the surfa…

> Whereas for linux users My wife has used Linux for many years successfully and has never used the CLI once.

So has my grandma

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#379
Why is there no simple workaround for this? Why is it dead in the water and why can't we use another mechanism to verify the update files with SHA1? It's all been done before [1]. This would be an improvement, as it enables the project to continue working without any handcuffed relationship to Microsoft.

[1] https://github.com/HyperSine/Windows10-CustomKernelSigners

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#380
Posted this earlier from a throwaway since my account wasn't able to reply for some odd reason and it was marked as dead:

Hello Jason!

I want to first thank you for all of your hard work developing Wireguard.

If I can find someone who is willing to put their name on it to help I definitely will, the problem is the spy agencies don't want your project to exist. It makes it harder to put resources to this. I've worked in security departments of certain companies and saw everything you could imagine.

Same for Mounir over at Veracrypt.

Both of you are developing some of the most important software that exists today.

Keep doing what you are doing by keeping everything in the open. User trust almost doesn't exist for these type of projects. Any hint of an issue would wipe that out in seconds.

This leads me to one question I do have for you zx2c4:

Why does Wireguard attempt to contact your servers and auto update on Android with no toggle to turn this off? It's a threat to everyone. Maybe it also does this on other platforms but I haven't tested them all.

I can think of reasons as to why you did this, none nefarious, but still it would be nice if you included that option so I don't have to patch each update to turn this off.

Thanks.

Post reply on HN