Live data from Hacker News

Microsoft terminates VeraCrypt account, halting Windows updates

404media.co

41–50 of 259 posts

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#41

Earlier quoted context omitted.

On Android, according to the Coalition Against Stalkerware, there are over 1 million victims of deliberately placed spyware on an unlocked device by a malicious user close to the victim every year. #2 is WAY more likely than #1. And that's on Android which still has some protections even with a sideloaded APK (deeply nested, but still detectable if you look at the right settings panels). As for #3; the point is that…

And where are the stats for people running their own firmware and are not running stalkerware for comparison? You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader?

The entirety of GrapheneOS is about 200K downloads per update. Malicious use therefore is roughly 5-1.

> You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader?

With a locked bootloader, the underlying OS is intact, meaning that the privileges of the spyware (if you look in the right settings panel) can easily be detected, revoked, and removed. If the OS could be tampered with, you bet your wallet the spyware would immediately patch the settings system, and the OS as a whole, to hide all traces.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#42

Earlier quoted context omitted.

Tradeoffs. Which is more likely here? 1. A customer wants to run their own firmware, or 2. Someone malicious close to the customer, an angry ex, tampers with their device, and uses the lack of Secure Boot to modify the OS to hide all trace of a tracker's existence, or 3. A malicious piece of firmware uses the lack of Secure Boot to modify the boot partition to ensure the malware loads before the OS, thereby permanent…

1. P(someone wants to run their own firmware) 2. P(someone wants to run their own firmware) * P(this person is malicious) * P(this person implants this firmware on someone else’s computer) 3. The firmware doesn’t install itself Yeah I think 2 and 3 is vastly less likely and strictly lower than 1.

As if the monetary gain of 2 and 3 never entered the picture. Malicious actors want 2 and 3 to make money off you! No one can make reasonable amounts of money off 1.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#43
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.

Computers should abide by their owners. Any computer not doing that is broken.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#44
Microsoft wants to control computers. This is why they came up with InsecureBoot - or ad-hoc eliminating accounts willy-nilly style. Microsoft kind of acts like Google here. It is also interesting that the US government is doing absolutely nothing against this despicable behaviour.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#45
post #29

They should have also picked up that WireGuard Creator account also got his account terminated

They did, just further into the article: > According to a post on Hacker News, the popular VPN client WireGuard is facing the same issue.

I meant to say, in the title. As Wireguard is way more popular than VeraCrypt...

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#46
post #19
post #15

There's a good reason everyone calls them microslop these days. The sooner we're all able to ditch this crappy company, the better - they're actively holding back the tech industry at this point

i remember years and years ago learning some posix/shell syntax and working in terminal. felt like my love for windows unraveled in real time. these days using windows... feel like i gotta take a shower after. like many i was just raised on windows it was the household operating system i had like 20 years of general computer usage under my belt on windows before i finally felt a mac trackpad for the first time. that…

> feel like i gotta take a shower after

I run Crossover and I feel like I gotta take a shower after. Just knowing there's a folder called drive_c on my Mac is the stuff of nightmares.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#47
post #19
post #15

There's a good reason everyone calls them microslop these days. The sooner we're all able to ditch this crappy company, the better - they're actively holding back the tech industry at this point

i remember years and years ago learning some posix/shell syntax and working in terminal. felt like my love for windows unraveled in real time. these days using windows... feel like i gotta take a shower after. like many i was just raised on windows it was the household operating system i had like 20 years of general computer usage under my belt on windows before i finally felt a mac trackpad for the first time. that…

Yeah. I felt in a similar manner when I moved to Linux. Microsoft seemed to make people dumber. I do actually use both Linux and Windows (Win10 only), largely for testing various things, including java-related software. But every time I use Windows, I am annoyed at how slow everything is compared to Linux. (I should mention that I compile almost everything from source on Linux, so most of the default Linux stack I don't use; many linux distributions also suck by default, so I have to uncripple the software stack. I also use versioned appdirs similar as to how GoboLinux does, but in a more free form.)

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#48
post #2

With Windows, you get what you pay for. In this case, that's an OS controlled by an unaccountable company that can take application software away from you. Related: If you're the customer, you're the product.

Windows actually isn't very cheap.

agree, because "free" can be neither "cheap" nor "expensive"

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#49
post #22

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.

If only people didn't install Ask Jeeves toolbars all over the place and then asked their grandson during vacations to clean their computer.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#50
post #7

Earlier quoted context omitted.

you can always either disable secureboot and driver signature verification, or (the better solution) just enroll your own certificate in your TPM and sign the driver with that...

> or (the better solution) just enroll your own certificate in your TPM and sign the driver with that... I'll tell Grandma that's what she needs to do.

your grandma is probably fine with BitLocker....
Post reply on HN