Live data from Hacker News

Microsoft terminates VeraCrypt account, halting Windows updates

404media.co

51–60 of 259 posts

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#51

Earlier quoted context omitted.

And where are the stats for people running their own firmware and are not running stalkerware for comparison? You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader?

The entirety of GrapheneOS is about 200K downloads per update. Malicious use therefore is roughly 5-1. > You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader? With a locked bootloader, the underlying OS is intact, meaning that the privileges of the spyware (if you look in the right settings panel) can easily be detected,…

LineageOS alone has around 4 million active users. So malicious use is at most 1:4, not 5:1.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#52

Earlier quoted context omitted.

Windows actually isn't very cheap.

agree, because "free" can be neither "cheap" nor "expensive"

It's not free at all. If you buy Windows through the official channels it's quite expensive. If you buy it on the grey market, it's dirt cheap, though.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#53
This is precisely why we can't allow platform-owners to be the arbiters of what software is allowed to run on our devices. Any software signing that is deemed to be crucial for ensuring grandma-safety needs to be delegated to independent third parties without perverse incentives.

This is what the Digital Markets Act is supposed to protect developers against. Have there been any news regarding EU's investigation into Apple? Last I remember they were still reviewing their signing & fee-collection scheme.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#54

Earlier quoted context omitted.

And where are the stats for people running their own firmware and are not running stalkerware for comparison? You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader?

The entirety of GrapheneOS is about 200K downloads per update. Malicious use therefore is roughly 5-1. > You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader? With a locked bootloader, the underlying OS is intact, meaning that the privileges of the spyware (if you look in the right settings panel) can easily be detected,…

Assuming that we accept your premise that the most popular custom firmware for Android is stalkerware (I don’t). This is of course, a firmware level malware, which of course acts as a rootkit and is fully undetectable. How did the coalition against stalkerware, pray tell, manage to detect such an undetectable firmware level rootkit on over 1 million Android devices?

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#55

Earlier quoted context omitted.

Ah, yes, the [insert super inconvenient and complex thing to do that most people don’t know, want or should do] will solve it! And when that fails, surely the user can just write their own OS, right? Bunch of skill-issued complainers we the users are.

Well, the hope was always that those of us inconvenienced by M$ would all collectively contribute to making Linux distros more convenient for everyone. But we can't ever seem to get inconvenienced enough to actually sufficiently mobilize and/or coordinate such an effort.

It does seem like linux is having its moment right now. there's the money and effort valve is putting into KDE making the steamdeck and steammachine polished for their hardware which helps all users of KDE. cachyos is making having a rolling distro really smooth and snappy on old hardware and making games work mostly ootb. stuff like winboat and wine will let you use the few windows apps you need. you are kinda stuck though if you want to use something like fusion360 or solidworks. freecad has improved quite a bit but it's still like gimp where it's slightly worse UX in a lot of ways.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#56

Earlier quoted context omitted.

you can always either disable secureboot and driver signature verification, or (the better solution) just enroll your own certificate in your TPM and sign the driver with that...

Ah, yes, the [insert super inconvenient and complex thing to do that most people don’t know, want or should do] will solve it! And when that fails, surely the user can just write their own OS, right? Bunch of skill-issued complainers we the users are.

I mean, the super-easy option would be to just use BitLocker for FDE. No hassles, just works. But I fugured since everyone here on HN hates MS I wouldn't even bring that up. Don't trust MS? Enroll yourown keys

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#57
post #43

Earlier quoted context omitted.

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.

Computers should abide by their owners. Any computer not doing that is broken.

I make the analogy with a company, because on that front, ownership seems to matter a lot in the Western world. It's like it had to have unfaithful management appointed by another company they're a customer of, as a condition to use their products. Worse, said provider is also a provider for every other business, and their products are not interoperable. How long before courts jump in to prevent this and give back control to the business owner?

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#58
A year ago I used Azure Trusted Signing to codesign FOSS software that I distribute for Windows. It was the cheapest way to give away free software on that platform.

A couple of months ago I needed to renew the certificate because it expired, and I ran into the same issue as the author here - verification failed, and they refused to accept any documentation I would give them. Very frustrating experience, especially since there no human support available at all, for a product I was willing to pay and use!

We ended up getting our certificate sourced from https://signpath.org and have been grateful to them ever since.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#59
post #30

Earlier quoted context omitted.

And what if that customer wants to run their own firmware, ie after the manufacturer goes out of business? "Security" in this case conveniently prevente that.

Tradeoffs. Which is more likely here? 1. A customer wants to run their own firmware, or 2. Someone malicious close to the customer, an angry ex, tampers with their device, and uses the lack of Secure Boot to modify the OS to hide all trace of a tracker's existence, or 3. A malicious piece of firmware uses the lack of Secure Boot to modify the boot partition to ensure the malware loads before the OS, thereby permanent…

#2 and #3 are fearmongering arguments and total horseshit, excuse the strong language.

Should either of those things happen the bootloader puts up a big bright flashing yellow warning screen saying "Someone hacked your device!"

I use a Pixel device and run GrapheneOS, the bootloader always pauses for ~5 seconds to warn me that the OS is not official.

Re: Microsoft terminates VeraCrypt account, halting Windows updates

#60
post #15

There's a good reason everyone calls them microslop these days. The sooner we're all able to ditch this crappy company, the better - they're actively holding back the tech industry at this point

Apple also holds back the tech industry in many ways. All companies seem willing to put profits before progress.
Post reply on HN