Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

81–90 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#81
post #6

They need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.

It's much worse than you think. Press coverage -> manual intervention is at best a bandaid covering up a major wound in a flaw that happens with independent software distribution.

The old model where the user decides which software or apps to run on their machine, is basically already replaced by a whitelist system that is managed by companies who have no interest or obligation to approve developers. Factors like ”being an individual”, an open source developer or god forbid reside outside the USA, you rely on a combination of L1 support doom loops, unjustifiable high recurring prices, kafkaesque and changing requirements, internal inconsistencies. Windows is the worst, but all platforms (except Linux) suffer from this and you can and will get hurt, delayed, and gaslit. If you haven’t, it’s just a matter of time.

I have been blocked for 6 months now with Digicert code cert renewal, for my app Payload, which will never get any media attention. The app doesn’t matter though, the approval process is per-entity (usually, a company). The point is that nobody gives a shit, because they have a monopoly/cartel and they start the validation process after they take your money.

If you are not an app publisher, the best way I can describe it is the ”pre-let’s encrypt” era of SSL certs, but more expensive, strict and ambiguous. In fact, I’ve never gone through any worse approval process in my life, and that includes applying for residency in two countries, business licenses, manual tax filings etc.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#82
post #76
post #39

This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't f…

I think it’s intentional, those encryption (at rest/transit) applications are outside of MS control and you can assume outside of potential backdoors by three letters agencies, bitlocker vs veracrypt? Of course bitlocker is favorable from their perspective. I wouldn’t be surprised if NSA already had a list of these applications and the strategies on how to cripple them or worse, compromise them.

Or found they’ve been compromised by someone else? ;)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#83

We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.

It should something like web certificates, you can bring your own.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#84
post #37

Earlier quoted context omitted.

You can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.

Afaict, you can't disable driver signature enforcement permanently without disabling secure boot.

You also get a huge watermark that says "Test Mode" that takes up the entire screen (not kidding)

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#85
Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer?

Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#86
post #65

Earlier quoted context omitted.

> Microsoft doesn't want to allow software that would allow the user to shield themselves I don't think Microsoft cares (about anything besides making mo' money), but there are plenty of (state) actors that can influence the decision-making at Microsoft when it comes to these issues. No tinfoil needed.

> No tinfoil needed. That's what Big Tinfoil wants you to believe!

Wait, what?! I was sure that the agenda of Big Tinfoil was to generate FUD so that we buy more tinfoil for our hats. Are you implying their agenda goes even deeper?

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#87
post #50
post #24

I am somewhat also concerned that this software was still being distributed on SourceForge.

Yes, I stopped using SourceForge after they started tampering with installers to put adware inside of them. It's a bit worrying that a sensitive app such as VeraCrypt is still distributed there.

That was 11 years ago, under DHI Group though. I don't think Slashdot Media have been up to the same shady stuff.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#89
This is always a problem when big mega-corporations are involved, be it Google or Microsoft. They want to control the platform.

We really need viable solutions. I have been using Linux since +21 years or so, so it does not affect me personally, but I think Linux needs to become really a LOT more accessible to normal people. And it really has not (on the desktop); all the various "improvements" on GNOME3 or KDE are basically pointless, they have not solved the underlying problem. Ideally problems should be auto-resolvable. If someone wants to use the proprietary nvidia driver, that should be a single click - on ALL Linux distributions. Instead you see some distributions have their own ad-hoc solution and other distributions have no easy solution (for simple people).

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#90
post #77

Earlier quoted context omitted.

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

Agree. Single point of failure. One developer, one account. Crazy.

Having multiple accounts wouldn't help, as Microsoft could easily suspend all the accounts of everyone associated with the project if any account looks suspicious. The single point of failure is Microsoft.
Post reply on HN