Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

391–400 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#391

First I was surprised to read the Veracrypt maintainers could be in this situation, then read the top comment where Wireguard maintainers are too (unless I misunderstood). Is this some malicious new program inside Microsoft to try and shutdown open source projects so they can push Windows products and solutions more?

It feels more like an automated block due to uncharacteristical increase in download activity. Something that it seems more and more companies are taking seriously is the cottage industry of scams involving less technically savvy downloading apps online and getting their information stolen. The motivation for this is probably the same as Google stopping side loading. Take that as you want.

And how would blocking the devs ability to sign the new version stop the spread of the already downloaded and still available old version?

I think you forgot we're talking about the kernel drivers specifically - normal scammers don't need that, they use AnyConnect downloaded from Chrome.

I think you also forgot to read it all and missed that it was supposedly some deanonymisation (ID verification) process that kicked it off, and missed that the dev has immediately verified themselves but then we're told they need to wait 2 months to wait.

Because.

It's not an automated process at this point.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#392
post #337

Earlier quoted context omitted.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

These services are designed such that security sort of depends on reviewing the programs that are allowed to run. Microsoft, Google and Apple all do this. It adds expense, annoyance, limitations, and really very little security. The contrasting approach, where one designs a platform that remains secure even if the owner is allowed to run whatever software they like, may be more complex but is overall much better. The…

> The contrasting approach, where one designs a platform that remains secure even if the owner is allowed to run whatever software they like

There's a lot that one can gripe about Amazon as a company about, but credit where credit is due -- their inversion of responsibility is game-changing.

You see this around the company, back to their "Accept returns without question" days of mail order.

Most critically, this inversion turns customer experience problems (it's the customer's problem) into Amazon problems.

Which turns fixing them into Amazon's responsibility.

Want return rates to go down because the blanket approval is costing the company too much money? Amazon should fix that problem.

Too often companies (coughGoogleMicrosoftMetacough) set up feedback loops where the company is insulated from customer pain... and then everyone is surprised when the company doesn't allocate resources to fix the underlying issue.

If false positive account bans were required to be remediated manually by the same team who owned automated banning, we'd likely see different corporate response.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#393
post #127

Earlier quoted context omitted.

likely chose to shut down rather than bend over, same as Lavabit a year prior. I find it more plausible than the other theory.

I went on a Wikipedia dive and discovered this funny bit regarding the court process surrounding Lavabit and FBI's desire of the TLS private keys. > The contempt of court was caused by Levison providing the keys printed in a tiny (4 point) font, which was deemed "largely illegible" by an FBI motion, which went on to complain that "To make use of these keys, the FBI would have to manually input all 2560 characters, an…

That's just stupid. Take 10 people, each enters the data independently, compare their versions and select the most common of each character. With 1 second per character they would finish in an hour, coffee break included. They just didn't want to bother.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#394
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Not exactly the same situation, but RustDesk has recently been removed from the official WinGet community repository because their automated scans have been blocking updates since v1.4.2 in September 2025.

https://github.com/rustdesk/rustdesk/discussions/13025 https://github.com/microsoft/winget-pkgs/pull/345601

tl;dr: ESET Antivirus flags RustDesk as a "Potentially Unsafe Application" because it is a remote administration tool, despite not flagging similar commercial products in the same way, and the WinGet Community repo policy is to block anything flagged as such. Since they were unable to update the repo the RustDesk team requested that the older versions be removed to prevent users from unknowingly installing old versions that could potentially be a security issue in the future. Apparently this has been an issue for a lot of applications especially in the VPN and remote control categories.

There is a discussion about how best to handle these sorts of situations where legitimate and desirable applications get flagged as "potentially unsafe" or "potentially unwanted" but so far it's just been a discussion with no actual changes proposed yet.

https://github.com/microsoft/winget-cli/issues/6107

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#395

Earlier quoted context omitted.

Why do folks act like windows isn't full of cli commands? First thing on any windows box is running debloat in powershell. Installing apps from a gui in Linux has been solved for a long time.

Having an excellent CLI doesn't preclude having an excellent GUI. No reason we can't have both. Also I hate linux repos with a passion, because they are optimized for CLI usuage, and (like the whole OS) the GUI parts are a total unoptimized afterthought. Never mind that they are a dumping ground for whatever code anyone shits out, with virtually zero management or curation. With a CLI you don't see this, with a GUI i…

> whatever code anyone shits out

downloading an exe is "whatever code anyone shits out" cause that's exactly what built binaries are

A lot of the programs you use on Windows are actually the exact same ones on Linux be it VLC or Chrome. If you want to download binaries directly "from the source" and run those.... well that was always allowed. But remember the entire stack delivering the entire internet to you at any time is open source code that "anyone shits out".

distros are catering to server installs most of the time. if you want a gui you install that entire stack but for most classic distros like debian the GUI is not the main thing. if you want a GUI from start to finish go with Fedora or the new KDE distro.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#396
post #317

Earlier quoted context omitted.

If I understand them correctly, the proposals are quite different. The US is effectively requiring the implementation of a third party verification service at computer set-up. The EUs approach validates an existing cryptographic identity that says you are over a certain age, without exposing your identification. Please correct me if I am wrong, this is what I read here.

Do you expect the EU to insist on a different solution once the US solution is in-place in all US-based operating systems?

Yes. They haven't had a problem implementing their own specific regulations before - like alternative app store requirements on iOS or the European editions of Windows.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#397

Earlier quoted context omitted.

Yeah, and the first comment beneath that mentions that the most recent version is signed with the "2011 CA" that the article I link to discusses being deprecated. My guess was that he got caught up in some house-cleaning. My theory being that he's still signing his code the way malware authors also do and got flagged by some automated review that's meant to force him to go get WHCP certified or whatever the new route…

The article you linked says the change is rolling out in April in evaluation mode. And if it were related to some kind of scan and malware flagging, the cert would have been revoked. It is not.

Fair enough. Thanks for weighing in.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#398
post #245

Earlier quoted context omitted.

We need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.

I understand the sentiment, but.. do you realize how much more expensive that would make all these services? I don’t know the number. But personally I think using the services and ‘simply’ only use them if the disappearance isn’t catastrophic and have the price be low or free while it works isn’t too bad a trade-off. Admittedly that’s a big ‘if.’

MS could literally double their global employee count with a fraction of what they spend on AI annually.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#399
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Thank you for the extra visibility on this issue. I'm in the exact same boat: account suspended, waiting for the 60 days appeal process. Hopefully it will be resolved swiftly!

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#400
post #258

Earlier quoted context omitted.

In the EU, under GDPR, it is legally required to explain automated profiling.

We have a EU dev we tried to have submit a GDPR request for human review on something on Facebook. There’s no apparent mechanism to do so. Support was clueless. The privacy email address responded weeks later with “not out department”.

That's because the correct department is legal. GDPR is a legal mechanism, not a support and privacy thing.

"I'm doing it wrong and it doesn't work" means you're doing it wrong, not that it doesn't work.

Post reply on HN