Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

51–60 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#51

It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.

And Microsoft will be happy to shut that one down because their incompetence.

So we'd better find a real solution now.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#52

maybe an old vulnerable signed driver can be used to load the new version :D. on a more seirous note, i think contact with a person at MS, likely via socials triggering that, might help here. It all depends on the reason for the ban/block/cancel. if they had a reason other than 'oops mistake' its likely just going to remain in place. (sadly, that is how MS is. if you care for privacy maybe go to BSD)

Who said vulnerable? Perhaps just a driver with less features.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#53

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

I think this is fundamentally an unsolvable problem and I'm not even sure it's worth pursuing.

Any large scale signing platform will have large oversights and be rendered useless. See the appstore / play store/windows...

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#54
post #29
post #25

Microsoft doing everything in their power to be assholes, as always

As much as I like bashing Microsoft, never underestimate people's capacity for incompetence, especially where large organizations are involved. I don't see how they would gain anything from this move.

It doesn’t help that they do that sort of shits AND mandate a microsoft account for logging in to windows. Also how much trust can you have that if you move your business to azure they will not randomly kill it. Incompetence or malice, almost doesn’t matter to the average user.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#55
post #40
post #4

It's like LibreOffice all over again: https://www.neowin.net/news/microsoft-bans-libreoffice-devel...

This is worrying on many levels. So Microsoft force you to create an account to use Windows and then they reserve the right to block you from your own account, thereby potentially making you lose access to all your OWN data. This is crazy and yet another reason to stop using Windows as soon as possible.

It's not your own data anymore if you gave it away.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#56
post #21

Earlier quoted context omitted.

Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway

What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.

Is it some entirely different process than providing hashes and a GPG signature?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#57
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

I tried to set up a partner account for driver signing last year (as a business entity) and it already seemed basically impossible. I think they're getting ready to just simply not allow it at all.

This is stupid. If Microsoft wants people to stop writing kernel drivers, that's potentially doable (we just need sufficient user mode driver equivalents...) but not doing that and also shortening the list of who can sign kernel drivers down to some elite group of grandfathered companies and individuals is the worst possible outcome.

But at this point I almost wish they didn't fix it, just to drive home the point harder to users how little they really own their computer and OS anymore.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#58
post #47
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Y'all need to form an alliance or something, get some press coverage (wireguard, veracrypt, libreoffice)

True, but really even if it gets resolved for them it should basically be a huge warning sign to everybody. Projects like those might get reinstated but it would only be because of how big they are that it would matter. Any person or small or 'undesirable' project would not get the same resolution.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#60
post #43
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

Or more likely, some automated security system flagged popular but suspicious apps for further review.
Post reply on HN