Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

411–420 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#411
post #164

https://community.osr.com/t/locked-out-of-microsoft-partner-... Could be a related issue to this? Maybe Microsoft just doesn’t want driver developers for whatever reason.

Most certainly it's related to this: https://techcommunity.microsoft.com/blog/hardware-dev-center...

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#412
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Is there a WireGuard version for Windows above 0.5.3 released in 2021?!

Hopefully soon, Microsoft-willing.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#413
post #146

Earlier quoted context omitted.

and yet... still unusable by the mass majority of people.

Linux is stuck because it's made and maintained by people who love linux. Look at popular unix based OS's - Android, MacOS, iOS.. Whats the first thing they do? Take the command line out back and shoot it. Whereas for linux users, their is this l33t h4cker festishization of only using a keyboard to do everything. All these distros have an extremely robust CLI under the hood, and an afterthought quasi GUI on the surfa…

Good. I'm sure this is a controversial take in our brave new world, but not everything has to be aimed at the lowest common denominator. It's refreshing to have something that isn't dumbed down for "the average user" and forces people to actually learn how to do something for a change.

I hope Linux never succumbs to the lowest common denominator and people who actually enjoy tinkering will always have somewhere to go and something to learn. If that's being stuck, I hope it stays stuck.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#414

Earlier quoted context omitted.

Their tweet was trying to help. Their comment here is bragging about how important they think they are.

> Their tweet was trying to help. Their comment here is bragging about how important they think they are. ah, well thank god you came in here and set them straight. i am sure the veracrypt maintainer is appreciative of your service.

Yeah, I blew the lid off of it!

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#415

Earlier quoted context omitted.

Perhaps not legally, but technically, you have an option: don't use the Microsoft Store. This isn't as wild a suggestion as it may seem to non-Windows users: the store is barely used by Windows users. You can get your own code signing certificate from a public CA, sign your own installer, and post it on your website. This is still the primary way that Windows software is distributed. Microsoft does not have a hand in…

I have found that MS still blocks my signed and timestamped .msi files for at least a few days. From saving the downloads in Edge and then via Smartscreen once you get it downloaded. If I submit it manually for every update it tends to go better. If more people download and install it whitelists faster. But that is highly annoying, orwellian bullshit. Might even be anti-competitive or downright illegal.

I see the same behavior with my MSIs. I've had better luck with my MSIXs. As much as I like being Store-free, I have a June 2025 release of an MSI-based app that still gets dinged by Edge and again by SmartScreen. A different MSIX-based app, with almost no users, gets dinged by Edge but not by SmartScreen. It's the same certificate. I can never be sure what other users are seeing, though.

tbh, I thought that I had built enough reputation on this particular MSI release, until testing it just now. Hate to see it :(

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#416

Earlier quoted context omitted.

>More regulation won't help here, because the regulation-maker is itself the hostile party. It's easy to paint the big gov as bad, but this is a case where unfortunately the populace seems to be in agreement with the big bad gov. While most US citizens support encryption, 76% or so, the vast majority 63% also favor government "backdoor" access for national security reasons. I guess either we believe in democracy or w…

What does democracy have to do with electronic encryption? Democracy existed before computers. There are legitimate reasons for governments to intercept information, with the correct oversight -- enforced legally in an "checks and balances" manner. The fact that there is a breakdown of trust between government and people won't be solved with more encryption.

A core tenet of Truecrypt + Veracrypt (developer guarantee) has always been no backdoors, even if requested by government.

If in a democratic society, the majority agrees that government should have backdoors (with the correct oversight). Then it follows that Veracrypt should be illegal as its use is not in alignment with the will of the majority.

I personally don't agree with the majority here but can you fault the logic?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#417

Earlier quoted context omitted.

We have a EU dev we tried to have submit a GDPR request for human review on something on Facebook. There’s no apparent mechanism to do so. Support was clueless. The privacy email address responded weeks later with “not out department”.

That's because the correct department is legal. GDPR is a legal mechanism, not a support and privacy thing. "I'm doing it wrong and it doesn't work" means you're doing it wrong, not that it doesn't work.

Even Facebook calls them "privacy rights".

And https://www.facebook.com/help/contact/178402648024363 doesn't work either. Black hole, as far as I can determine.

Their chatbot, when asked, sends you to https://help.meta.com/support/privacy/ and says:

> To submit a GDPR objection request on Facebook, you can use the Privacy Rights Request channel.

> Select Facebook as the product you want to submit an objection about.

> Choose the option "How can I object to the use of my information" and follow the instructions.

But that option doesn't exist.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#418
VLayer (my project) scans healthcare codebases for HIPAA compliance issues before they reach production. One thing I learned building it: developers rarely think about encryption until it's too late. Tools like VeraCrypt solve the "data at rest" problem, but the bigger issue in healthcare software is unencrypted data in logs and API responses — stuff that's much harder to audit manually.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#419

Earlier quoted context omitted.

It has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and…

It would not surprise me if these actions are coming at the requests of governments. Strong encryption is one of the few things that challenges their monopoly on information; they have a very strong incentive to apply political pressure to the maintainers of these projects to, well, stop maintaining the projects. We've seen this in overt actions that the EU takes; in more covert actions that the U.S. government is su…

VLayer (my project) scans healthcare codebases for HIPAA compliance issues before they reach production. One thing I learned building it: developers rarely think about encryption until it's too late. Tools like VeraCrypt solve the "data at rest" problem, but the bigger issue in healthcare software is unencrypted data in logs and API responses — stuff that's much harder to audit manually.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#420

Earlier quoted context omitted.

I would also like to know why is it excluded from Archive.org https://web.archive.org/web/20260000000000*/https://www.true...

This can be done by Archive.org doing it for whatever reason (asked, on their own, etc) or it can be triggered by the current owner of the domain modifying robots.txt I believe.

Yes: https://gist.github.com/danielhickman/38d6c7599d71c3e7dc48ca...
Post reply on HN