Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

501–510 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#501

Earlier quoted context omitted.

If it was an excuse to get your data there would be some data-getting involved. It may be hard for you to believe, but lots of people really do want parental controls that actually work and are bound by the force of law.

Yes that may be true, but parents are being misguided by efforts that are trying to control aspects of data. If you, as a parent, make yourself open to this attack, you will find that you are making us less free of a society by expecting others to parent for you.

If you oppose minimal, sensible parental controls, you open the door to whatever someone can jam down our throats that also happens to implement parental controls as a side effect.

If you oppose the law to force liquor stores to deny service to minors, but people are still upset about minors getting alcohol, you have no right to be surprised when the next proposal is to ban alcohol for everyone, and you have no right to be surprised if it passes.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#502

Earlier quoted context omitted.

Simple attestation is very useful for the case where a parent gives a child access to a computer and wants that computer to block porn. That's the use case everyone is clamoring for, and asking the root user "how old is this user?" solves it in a simple, open, privacy-preserving way. Everybody wins, except the teenager who wants to watch porn. If this were not legally mandated, everyone would support it as a useful f…

If you think you are anyone can stop motivated teenagers from watching porn then I have a bridge to sell you. That is such an absurd goal that you really should be asking what the real motivations for this are.

If you think you are anyone can stop motivated teenagers from getting alcohol then I have a bridge to sell you. That is such an absurd goal that you really should be asking what the real motivations for [forcing liquor stores not to serve minors] are.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#503

Earlier quoted context omitted.

The other day I tried to create a Github account and was repeatedly told I am fraudulent. Nothing else. Try again later, it says. This is the same thing that's happened every time I've tried to have a Microsoft account. I don't think Microsoft wants to have customers who aren't rich.

Maybe some bot signed up using your email and then did bot things on it. I've had that happen a lot over the years. My Microsoft account is still stuck in German because that's the language the bot used when creating the account (to spam X-Box apparently).

Brand new email account.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#504

Earlier quoted context omitted.

If arbitrary app stores are allowed without restrictions, isn't that equivalent to allowing installation of any apps?

That's the idea! "Allow" the user to install any apps they choose. (I put "allow" in quotes, to emphasize how bizarre it is that a few platform vendors get to decide what all of humanity is "allowed" to do with their computing.)

GP here. I agree in spirit but there’s a technical difference between ”approved to distribute” and ”approved in an App Store”. Specifically, you can distribute software for Windows and Mac outside of their stores, but you still need to have a code cert which means you’re under their mercy. This is the model Google wanted to transition Android to recently: keeping the APK path (no App Store) but gatekeep developers through signature enforcement etc.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#505

Earlier quoted context omitted.

Actually, Windows by default will not trust code signed by CAs that issue certificates to websites. It will only trust code signed by CAs that are approved for code-signing, which isn't a very large set anymore. Moreover, recent CA/Browser Forum policies forbid dual-use CAs anyway. If Let's Encrypt issues you a certificate for a web site, it cannot be used for code signing. It's possible that they could start issuing…

> However, domain validation is almost completely irrelevant to, and insufficient for, code signing. It's actually the only thing that provides any kind of assurance to users. It's not like end users know if FuzzCo is the correct developer for FooApp but they know fooapp.com.

A web site is identified by its URL, which contains its domain. Any good HTTPS implementation cross-checks the requested domain against the SANs of the cert, and does so automatically.

There is nothing in a piece of random software obtained from some random source that authoritatively connects it with a particular domain. Without bringing an App Store or other walled garden into the picture, the operating system must evaluate an executable file according to the contents of the file itself. On cold launch, the information in the certificate can be presented to the user, and the certificate issuer can be checked against the O/S trust store, but nothing equivalent to the HTTPS domain check can be done.

DV certs work for the web because of that intrinsic connection between web site and domain. They fail for arbitrary software because of the lack of such a connection. The trustworthiness of code-signing certs comes from the relatively difficult process necessary to obtain them, and not the name attached to them. The identifiable legal entity to which the certificate was issued is more useful to the O/S vendor, as a harder-to-evade ban target, than it is to the end user.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#506

Earlier quoted context omitted.

It would not surprise me if these actions are coming at the requests of governments. Strong encryption is one of the few things that challenges their monopoly on information; they have a very strong incentive to apply political pressure to the maintainers of these projects to, well, stop maintaining the projects. We've seen this in overt actions that the EU takes; in more covert actions that the U.S. government is su…

>More regulation won't help here, because the regulation-maker is itself the hostile party. It's easy to paint the big gov as bad, but this is a case where unfortunately the populace seems to be in agreement with the big bad gov. While most US citizens support encryption, 76% or so, the vast majority 63% also favor government "backdoor" access for national security reasons. I guess either we believe in democracy or w…

I'd be very wary about such specific surveys, because they're often very much not conducted in a scientifically responsible manner, and based on actual studies across the spectrum of political issues there's basically no alignment between public opinion/preferences and actual policymaking in the US.

Could this be the one exceptional case where people agree with the direction of policymaking? Sure. Is that likely? No, not really.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#507

Earlier quoted context omitted.

Thanks for sharing your experience. I have been code signing releases for over a decade as an indie publisher myself, until I found myself effectively iced out by the HSM requirement, the increased cost, and the shortened cert lifetimes, which, as someone with certain executive order dysfunctions, I already had a hard time being on top of with the old (multi-year) lifetimes. I just migrated to MS artifact signing and…

I believe you. I also found that many CAs will not deal with a solo developer; that's real. But Sectigo continues to offer HSMs to solo developers. The link I used is [1], you buy the HSM along with your first certificate and they ship it to you. $300/year for the cert, $90 one-time for the HSM. That's not cheap but I think for specific developers looking for an escape from the store, it's a good price for freedom. T…

For comparison, my code signing cert via Azure (no Microsoft store account required, can be used to self-publish binaries/installers the old fashion way) is $10/month, or about a third of the price Sectigo is charging you. I figured it was worth trying this route first, though I had to write my own basic tooling around it.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#508
post #426

I run a dual boot of windows and am currently dauly-driving CachyOS quite happily. I've been playing some Crimson desert and got some occasional crashes... But any other game I have has run smoothly. Their GUI tools for package management are thin wrappers on CLI tools, but are enough hand-holding that most people should navigate it fine. More devices worked out of the box for my with Linux than Windows. Just like if…

Cachy pushed a Limine update last weekend without any testing. It broke everyone with secure boot signing. Head proton versions are great, but games tend to turn into a laggy mess after a couple of hours and need regular restarts. It's decent, but it's not all roses at all, and I wouldn't inflict it on non-techies yet.

Ah, I disabled secure boot assuming it's pointless and wouldn't work with arch and dual booting anyway. Maybe I have more to learn.

Perhaps cachyos should maintain LTS metapackages for more than just the kernel. Video drivers, boot managers and whatnot.

For a "non-gamer" I would probably keep them on Fedora or even Debian.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#509
post #67

Earlier quoted context omitted.

Sure, for now... I simply don't believe it will stop at "simple attestation", because we all know that simple attestation is practically useless, but once the various distros accept this "trivial" inconvenience, "Age verification 2" with harsher requirements will soon be on the way. I would be ecstatic to be proved wrong on this, but experience tells me that is not likely to happen.

We all know it's not about age, it's about user identity. As above, it's clearly a wedge so it's not rhetorical to observe more invasive and controlling features are coming.

I wouldn't be surprised if it is being done to help microslop and AI companies lock in their profit margins.

Right now, if a handful of tech companies crater they'll take the whole world's financial systems out with them, so the government could easily be made complicit in any scheme they can conceive of to bolster their finances.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#510

Earlier quoted context omitted.

In most cases you can put your computer secure boot in setup mode and roll your own keys.

Until they making CA a requirement, then disable changing the CA settings and it defaults to Microsoft. Then you are fucked.

That would make extremely inconvenient if MS ever need to revoke a certificate.
Post reply on HN