Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

441–450 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#441
post #167
post #40

Earlier quoted context omitted.

This is worrying on many levels. So Microsoft force you to create an account to use Windows and then they reserve the right to block you from your own account, thereby potentially making you lose access to all your OWN data. This is crazy and yet another reason to stop using Windows as soon as possible.

I know it's not what people want to hear but my response to a lot of the comments here is just a general, I agree, it's time to stop using Windows. They won't let you secure your drive the way you want. They won't let you secure your network the way you want (per the top-level comment about Wireguard). In so doing they are demonstrating not just that they can stop you from running these particular programs but that t…

Nah, it's simpler. Microsoft just lost sense of UX and touch with the reality to their own internal management vibes.

Look at the Windows start menu. It used to be trivial to switch users. Two clicks, one to open the user list, another to switch - done. Now it's four: user panel, three-dots, switch user, pick user.

Look at the login sequence. They want their Windows Hello and they don't care if it works well or not - no way to get a pin or password prompt instantly, you gotta click three times (one to show a method picker, another to pick PIN entry, and lastly one to focus the goddamn field) despite no reasons to hide this UI.

It's not like they're trying to scam or sell user into something. It looks like some internal decision-makers that don't ever dogfood their decisions losing touch with the common sense.

Apple has that too, and this rot spreads elsewhere. But it's not intently malicious, a lot of things simply don't make sense - just total lack of self-reflection capabilities at the corporate level.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#442

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway

Actually, Windows by default will not trust code signed by CAs that issue certificates to websites. It will only trust code signed by CAs that are approved for code-signing, which isn't a very large set anymore. Moreover, recent CA/Browser Forum policies forbid dual-use CAs anyway. If Let's Encrypt issues you a certificate for a web site, it cannot be used for code signing.

It's possible that they could start issuing separate certificates upon specific request for code signing purposes, but it's doubtful they would be willing to meet Microsoft's requirements for such certificates, so their code-signing CA would not be added to Windows's trust store, rendering the certificates it issues useless.

The ACME protocol, the key automation technology that makes Let's Encrypt possible, performs domain validation only. It verifies that you, the person (or bot) making the request, are an authorized administrator of the DNS records, or port-80 HTTP server, for that domain. This is directly relevant to, and generally considered sufficient for, HTTPS.

However, domain validation is almost completely irrelevant to, and insufficient for, code signing. Microsoft's rules (and Apple's, incidentally) require establishing the identity of a legal person (individual, or preferably, company). There is no way the ACME protocol can do this, which means that the process is totally out of Let's Encrypt's wheelhouse.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#443

Update from a VP at Microsoft: https://x.com/shanselman/status/2041977121686585396?s=46

Amazing that their processes failed and didn't work, so the VP lashes out at everyone calling them out for it. It's not like Microslop isn't a huge organization that is the critical component here. Extremely unprofessional response, I'll reiterate, they see regular users as a nuisance.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#444

Earlier quoted context omitted.

What does democracy have to do with electronic encryption? Democracy existed before computers. There are legitimate reasons for governments to intercept information, with the correct oversight -- enforced legally in an "checks and balances" manner. The fact that there is a breakdown of trust between government and people won't be solved with more encryption.

A core tenet of Truecrypt + Veracrypt (developer guarantee) has always been no backdoors, even if requested by government. If in a democratic society, the majority agrees that government should have backdoors (with the correct oversight). Then it follows that Veracrypt should be illegal as its use is not in alignment with the will of the majority. I personally don't agree with the majority here but can you fault the…

Most forms of democracy do not have a direct correspondence between "the will of the people" and the actual policies enacted. As another poster mentioned, tyranny of the majority is a thing, and robust democracies have evolved institutions to deal with it. Otherwise there's nothing stopping the majority from periodically voting the minority off the island, Survivor style, until only a single dictator remains.

In the U.S. in particular, there's strong respect for individual rights enshrined in the Constitution, and a key role of the judicial branch is ensuring that those rights are respected regardless of what the majority thinks. The majority cannot enslave the minority, for example, regardless of what the legislature votes. Nor can it deprive it of speech or free assembly, or guns, or a right to trial by jury.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#445

Earlier quoted context omitted.

It would not surprise me if these actions are coming at the requests of governments. Strong encryption is one of the few things that challenges their monopoly on information; they have a very strong incentive to apply political pressure to the maintainers of these projects to, well, stop maintaining the projects. We've seen this in overt actions that the EU takes; in more covert actions that the U.S. government is su…

>More regulation won't help here, because the regulation-maker is itself the hostile party. It's easy to paint the big gov as bad, but this is a case where unfortunately the populace seems to be in agreement with the big bad gov. While most US citizens support encryption, 76% or so, the vast majority 63% also favor government "backdoor" access for national security reasons. I guess either we believe in democracy or w…

> vast majority 63% also favor government "backdoor" access for national security reasons.

Don't do math that way! That math is illegal! Good boys and girls don't keep secrets!

These people sound ridiculous

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#446
post #288

Earlier quoted context omitted.

You are not wrong that regulation is desperately needed, and that EU is doing good things. However, even the EU which are doing the right thing on an anti-trust pro-competition basis, they fundamentally succumb to the same misconception – that middlemen are necessary at all. The EU doesn’t care about the App Store model, they care about the App Store monopoly. They are right about that, but the solution isn’t alterna…

If arbitrary app stores are allowed without restrictions, isn't that equivalent to allowing installation of any apps?

That's the idea! "Allow" the user to install any apps they choose. (I put "allow" in quotes, to emphasize how bizarre it is that a few platform vendors get to decide what all of humanity is "allowed" to do with their computing.)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#447

Earlier quoted context omitted.

Isn't this Microsoft abusing their quasi-monopoly as a consumer PC OS vendor? If it weren't for the current administration, I'd say it's time for regulatory action.

The time for regulatory action against Microsoft was thirty years ago and the need for it has only grown since then. The FTC wasn't doing their job between 1980-2020 because of their ridiculous standard of, "if it doesn't raise consumer prices, it must be allowed." This lead to massive consolidation in many industries which of course ended up raising prices and hurting consumers anyway. Recently they've had some wins…

> "if it doesn't raise consumer prices, it must be allowed."

are there any books or good articles with good sources about this? I'm very interested in what happened in the 80s through the mid 90s.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#448

Earlier quoted context omitted.

Because even though you don’t like a thing, the entire world of business uses it. Hold your nose and work on WINE if you need to think that way. But MS has moats, and office is one of the widest.

I think business are going to be forced to change their thinking on this. Im not interesting in emulating windows progs in wine. I switched to Thunderbird a long time ago and other programs that give me the features I need with-out sacrificing my freedom.

Thunderbird UI is absolute trash.

LibreOffice also has bad UI choices and glitches.

It’s not like we’re talking VLC vs OS Media Player here.

You can stomp your feet, but the world uses Exchange and Office and not for no reasons at all.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#449

Earlier quoted context omitted.

It’s become neigh impossible to get your own code signing cert these days. The 2025 update from the CA forum required code signing certs to be short lived (no more three or five year certs) and stored exclusively on an HSM. As a result, most companies cross-signing these certs have moved to a subscription PaaS model where you are issued a cert but never receive custody of it, and perform signing via their APIs, and a…

I was afraid of the HSM at first but for an open source developer (rather than a big company) I found it wasn't a big deal. I can't sign in GitHub Actions and I have a USB stick that lights up when I sign releases, but it hasn't been a blocker. I got mine from Sectigo Store. This isn't hypothetical, I really did it, I've got the HSM, it works. It wasn't difficult. It just cost some money and a little bit of time. "Ni…

I must say your experience is interesting. I am using https://signmycode.com/sectigo-code-signing, but I have chosen Install on Existing Token (Google Cloud KMS), and it's quite easy for me to handle the stuff. I am not scared of key storage or security issue nor password protection or forget issue.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#450

Earlier quoted context omitted.

What does democracy have to do with electronic encryption? Democracy existed before computers. There are legitimate reasons for governments to intercept information, with the correct oversight -- enforced legally in an "checks and balances" manner. The fact that there is a breakdown of trust between government and people won't be solved with more encryption.

A core tenet of Truecrypt + Veracrypt (developer guarantee) has always been no backdoors, even if requested by government. If in a democratic society, the majority agrees that government should have backdoors (with the correct oversight). Then it follows that Veracrypt should be illegal as its use is not in alignment with the will of the majority. I personally don't agree with the majority here but can you fault the…

That's why specialized agencies exist within the government body: FCC, FDA, etc.

aka leave it to the experts because the majority isn't qualified to make such decisions.

Post reply on HN