Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

71–80 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#71
post #21

Earlier quoted context omitted.

What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.

Is it some entirely different process than providing hashes and a GPG signature?

Well, yes. Just look at OP and Jason struggling to get their code signed.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#72
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

Maybe time for a custom license that would require M$ to sign up for special T&Cs if they want to use this software?

Who cares if it's OSI-approved or not, a line saying "M$, Google, and the like need written permission for every use case" would help to make those leeches honest. Just learn from the JSLint example.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#73

Earlier quoted context omitted.

Yeah but isn't the point of these certificates to express trust ? The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit. Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a C…

who on planet earth trusts a piece of software because Microsoft signed it?

Trust isn't binary, it's a spectrum. A signature is a signal that should increase trustworthiness. Not the strongest signal, perhaps even a weak one, but it's not zero.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#74

It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.

Probably not French though, give how hostile it appears to be to encryption/security related projects (GrapheneOS had a good arguments re: that)

The author is now based in Japan, and even owns a veracrypt.jp domain. Meanwhile, the old veracrypt.fr domain redirects to veracrypt.io.

Seems rather clear that he doesn't want French jurisdiction.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#75
post #43

Earlier quoted context omitted.

Now this is even more alarming! Wireguard's creator has their Microsoft account suspended... Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic!

Or more likely, some automated security system flagged popular but suspicious apps for further review.

Maybe they let Mythos loose and it suggested the safest approach was to remove access ;)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#76
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

I think it’s intentional, those encryption (at rest/transit) applications are outside of MS control and you can assume outside of potential backdoors by three letters agencies, bitlocker vs veracrypt? Of course bitlocker is favorable from their perspective.

I wouldn’t be surprised if NSA already had a list of these applications and the strategies on how to cripple them or worse, compromise them.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#77
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

Agree. Single point of failure. One developer, one account. Crazy.
Post reply on HN