Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

61–70 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#61
post #34

Looks like Linux and some of the BSDs are the only remaining truly open OSes.

Well, of course. Have the other commercial offerings every been "truly open OSes"?

So far I haven't had much concrete reason for my family to switch away from Windows. The updates maybe, needing to pay for a new license and the UI changes are like pulling the chair out from under them, especially as they get older (Windows 7 was hard for my grandma, thankfully they left 10 mostly alone but 11 is quite different again so she's currently staying on 10 — not that her hardware supports 11 anyway but that's fixable), but it's either learning the new Windows UI, let's say ten storypoints of newness, or learning some Linux desktop environment, even if it's Mint which is similar to 7/XP it's not quite the same either and probably like 15 storypoints at minimum, even if then you're done for much longer

But if OSes are being locked down and software has trouble distributing security updates through official repositories for Windows... that's a good reason to finally make the switch. Same as why my family is on Android: I can install f-droid, disable the google store, and don't have to worry about them installing malware / spyware / adware

There's different degrees of openness. Android till 2026 was an acceptable compromise (let's see how it goed forwards). Windows is also on the decline with their account policy, not sure about this certificate revocation thing (thankfully haven't had to deal with it yet; I'm not a user myself) but it sounds like they're moving to a walled garden also

When the degree changes and gets even less open, yeah you can say "well of course, they were never truly open, they're commercial" but it's still a change and might lead people to alter their choices

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#62
post #48

Looks like Linux and some of the BSDs are the only remaining truly open OSes.

Except compulsory age verification in Linux is now becoming a real threat. Some Linux distros are actively against this but many are not seemingly interested in fighting it: CachyOS, Ubuntu, Fedora and others. Age Verification is the thin end of a much bigger wedge in "open" OS's

the current law requires no verification at all simple attestation, you could put in _any_ age. it also does not effect linux distros as a whole, only distros in jurisdictions with the laws.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#63
post #43
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

> Microsoft doesn't want to allow software that would allow the user to shield themselves

I don't think Microsoft cares (about anything besides making mo' money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues.

No tinfoil needed.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#65
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

> Microsoft doesn't want to allow software that would allow the user to shield themselves I don't think Microsoft cares (about anything besides making mo' money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. No tinfoil needed.

> No tinfoil needed.

That's what Big Tinfoil wants you to believe!

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#67
post #48

Earlier quoted context omitted.

Except compulsory age verification in Linux is now becoming a real threat. Some Linux distros are actively against this but many are not seemingly interested in fighting it: CachyOS, Ubuntu, Fedora and others. Age Verification is the thin end of a much bigger wedge in "open" OS's

the current law requires no verification at all simple attestation, you could put in _any_ age. it also does not effect linux distros as a whole, only distros in jurisdictions with the laws.

Sure, for now... I simply don't believe it will stop at "simple attestation", because we all know that simple attestation is practically useless, but once the various distros accept this "trivial" inconvenience, "Age verification 2" with harsher requirements will soon be on the way.

I would be ecstatic to be proved wrong on this, but experience tells me that is not likely to happen.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#68

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

On the source code side, I quite like the way Guix does things, i.e. needing every commit to be gpg-signed. They even have a handy tool for verifying the repo[0] but I'm not sure how viable this is for non-OSS projects.

[0]: https://guix.gnu.org/manual/devel/en/html_node/Invoking-guix...

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#69
post #21

Earlier quoted context omitted.

Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway

What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.

Microsoft signed the Crowdstrike updates. I don't think a CA signing a piece of malware is a realistic thing to be concerned about.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#70

It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.

Yeah but isn't the point of these certificates to express trust ? The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit. Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a C…

who on planet earth trusts a piece of software because Microsoft signed it?
Post reply on HN