Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

381–390 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#381

Earlier quoted context omitted.

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and…

It would not surprise me if these actions are coming at the requests of governments. Strong encryption is one of the few things that challenges their monopoly on information; they have a very strong incentive to apply political pressure to the maintainers of these projects to, well, stop maintaining the projects. We've seen this in overt actions that the EU takes; in more covert actions that the U.S. government is su…

>More regulation won't help here, because the regulation-maker is itself the hostile party.

It's easy to paint the big gov as bad, but this is a case where unfortunately the populace seems to be in agreement with the big bad gov. While most US citizens support encryption, 76% or so, the vast majority 63% also favor government "backdoor" access for national security reasons.

I guess either we believe in democracy or we don't. It could be said that if Veracrypt isn't/can't be backdoor'd, perhaps the gov is simply implementing the will of the people :( via Microsoft.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#382

Earlier quoted context omitted.

I was afraid of the HSM at first but for an open source developer (rather than a big company) I found it wasn't a big deal. I can't sign in GitHub Actions and I have a USB stick that lights up when I sign releases, but it hasn't been a blocker. I got mine from Sectigo Store. This isn't hypothetical, I really did it, I've got the HSM, it works. It wasn't difficult. It just cost some money and a little bit of time. "Ni…

Thanks for sharing your experience. I have been code signing releases for over a decade as an indie publisher myself, until I found myself effectively iced out by the HSM requirement, the increased cost, and the shortened cert lifetimes, which, as someone with certain executive order dysfunctions, I already had a hard time being on top of with the old (multi-year) lifetimes. I just migrated to MS artifact signing and…

The sectigo HSM is just a USB stick they actually mail you, so it's not onerous.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#383

Earlier quoted context omitted.

It would not surprise me if these actions are coming at the requests of governments. Strong encryption is one of the few things that challenges their monopoly on information; they have a very strong incentive to apply political pressure to the maintainers of these projects to, well, stop maintaining the projects. We've seen this in overt actions that the EU takes; in more covert actions that the U.S. government is su…

>More regulation won't help here, because the regulation-maker is itself the hostile party. It's easy to paint the big gov as bad, but this is a case where unfortunately the populace seems to be in agreement with the big bad gov. While most US citizens support encryption, 76% or so, the vast majority 63% also favor government "backdoor" access for national security reasons. I guess either we believe in democracy or w…

Tyranny of majority is a thing. It's something mature democracies are aware of and have the ability to defend against.

We're in an interesting spot here and the tension is tangible.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#384

Earlier quoted context omitted.

As I've said elsewhere, freshmeat.net was better :-)

For project discovery, definitely -- but not as a source code repository. Wow, we're dating ourselves on this, but I remember when it was a big deal that SF.net added SVN support. They apparently didn't turn off CVS until 2017!

Yeah, I remember introducing a web dev company to SVN in about oh maybe 2006. Prior to that their "version control" was a webroot full of shit like "index.php", "index.php.old", "index.php.broken", "index.ryan.donottouch.php", "indexTUESDAY.php" and so on.

Yeah no, guys, that's not what I meant. Let me just show you this real quick...

I wonder if enough of freshmeat still exists on the Wayback machine to make a clone, maybe a skin for forgejo?

Simpler times, simpler everything.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#385
post #288

Earlier quoted context omitted.

Some countries (the EU in general) are already doing things about this. Owning the app store means you are a monopoly and now the only question is are you illegal by the local laws which vary. You can/should write your congressman (or whatever they are called in your country) and get better laws in place.

You are not wrong that regulation is desperately needed, and that EU is doing good things. However, even the EU which are doing the right thing on an anti-trust pro-competition basis, they fundamentally succumb to the same misconception – that middlemen are necessary at all. The EU doesn’t care about the App Store model, they care about the App Store monopoly. They are right about that, but the solution isn’t alterna…

If arbitrary app stores are allowed without restrictions, isn't that equivalent to allowing installation of any apps?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#386

What sucks about this, is due to implementation,Windows is the only way to achieve some stuff in Veracrypt. For example: doing full system partition encryption, and the Hidden OS install that only Veracrypt can do- requires Windows with the computer set to MBR rather than UEFU. I had hoped we'd see more of the plausible deniability tech at the OS level But aside from one or two experimental attempts, also presented a…

> Windows is the only way to achieve some stuff in Veracrypt

On the other hand, if you get rid of Windows you don't even need Veracrypt.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#387

Earlier quoted context omitted.

"Never attribute to malice that which is adequately explained by stupidity"

I'm more convinced than ever that this aphorism has it completely backwards.

Or it's being spread by the malicious actors, like "money doesn't buy happiness".

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#388

Earlier quoted context omitted.

I was afraid of the HSM at first but for an open source developer (rather than a big company) I found it wasn't a big deal. I can't sign in GitHub Actions and I have a USB stick that lights up when I sign releases, but it hasn't been a blocker. I got mine from Sectigo Store. This isn't hypothetical, I really did it, I've got the HSM, it works. It wasn't difficult. It just cost some money and a little bit of time. "Ni…

Thanks for sharing your experience. I have been code signing releases for over a decade as an indie publisher myself, until I found myself effectively iced out by the HSM requirement, the increased cost, and the shortened cert lifetimes, which, as someone with certain executive order dysfunctions, I already had a hard time being on top of with the old (multi-year) lifetimes. I just migrated to MS artifact signing and…

I believe you. I also found that many CAs will not deal with a solo developer; that's real. But Sectigo continues to offer HSMs to solo developers. The link I used is [1], you buy the HSM along with your first certificate and they ship it to you. $300/year for the cert, $90 one-time for the HSM. That's not cheap but I think for specific developers looking for an escape from the store, it's a good price for freedom. The HSM is a USB stick with an LED on the back. The software is called "SafeNet Authentication Client" and it sets up the certificate access in your Windows Certificate Store so that signtool can use it. Prompts for the password every time (annoying).

[1] https://comodosslstore.com/code-signing/comodo-individual-co...

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#389

Earlier quoted context omitted.

Why "Western" corporations that promote censorship? Non-western censorship is allowed?

They don't care as much about things like this

About what things? Winnie the Pooh for example?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#390
post #258
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

In the EU, under GDPR, it is legally required to explain automated profiling.

We have a EU dev we tried to have submit a GDPR request for human review on something on Facebook.

There’s no apparent mechanism to do so. Support was clueless. The privacy email address responded weeks later with “not out department”.

Post reply on HN