Earlier quoted context omitted.
It's to serve the regulators. The Radio Equipment Directive essentially requires the use of secure boot fir new devices.
I happen to like knowing that my mobile device did not have a ring 0 backdoor installed before it left the factory in Asia. SecureBoot gives me that confidence.
Microsoft terminates VeraCrypt account, halting Windows updates
81–90 of 259 posts
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#82Earlier quoted context omitted.
I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.
> id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with The firmware of the device being a binary blob for the most part... Not like I trust it to begin with. Whereas my open source Linux distribution requires me to disables SecureBoot. What a world.
There's also plenty of folks combining this with TPM and boot measurements.
The ugly part of SecureBoot is that all hardware comes with MS's keys, and lots of software assume that you'll want MS in charge of your hardware security, but SecureBoot _can_ be used to serve the user.
Obviously there's hardware that's the exception to this, and I totally share your dislike of it.
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#83Earlier quoted context omitted.
> or (the better solution) just enroll your own certificate in your TPM and sign the driver with that... I'll tell Grandma that's what she needs to do.
Why would you put Grandma on VeriCrypt in the first place? It's the more 'difficult' option for FDE.
In my limited experience with bitlocker, the disk is decryptable automatically as long as it's in the original motherboard.
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#84A year ago I used Azure Trusted Signing to codesign FOSS software that I distribute for Windows. It was the cheapest way to give away free software on that platform. A couple of months ago I needed to renew the certificate because it expired, and I ran into the same issue as the author here - verification failed, and they refused to accept any documentation I would give them. Very frustrating experience, especially s…
For what it’s worth, Trusted Signing verification has been a moving target over the last 12 months. It was open for individuals, then it was closed to anyone except (iirc) US businesses with DUNS numbers, then it opened again to US based individuals (and a few other countries perhaps). My completely uninformed guess was that someone had done something naughty with Trusted Signing-issued code signing certificates. Any…
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#85Earlier quoted context omitted.
I happen to like knowing that my mobile device did not have a ring 0 backdoor installed before it left the factory in Asia. SecureBoot gives me that confidence.
No it doesn't? The factory programs in the secure boot public keys
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#86Earlier quoted context omitted.
I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.
And what if that customer wants to run their own firmware, ie after the manufacturer goes out of business? "Security" in this case conveniently prevente that.
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#87Earlier quoted context omitted.
Ah, yes, the [insert super inconvenient and complex thing to do that most people don’t know, want or should do] will solve it! And when that fails, surely the user can just write their own OS, right? Bunch of skill-issued complainers we the users are.
I mean, the super-easy option would be to just use BitLocker for FDE. No hassles, just works. But I fugured since everyone here on HN hates MS I wouldn't even bring that up. Don't trust MS? Enroll yourown keys
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#88Earlier quoted context omitted.
Why would you put Grandma on VeriCrypt in the first place? It's the more 'difficult' option for FDE.
What's easier, and bitlocker doesn't count. I want my FDE to be based on a password or a keyfile, not simply by some code in the motherboard. I want it encrypted until I, the operator, provide some data to unlock. In my limited experience with bitlocker, the disk is decryptable automatically as long as it's in the original motherboard.
Wat? Bitlocker is the answer to your question.
> In my limited experience with bitlocker, the disk is decryptable automatically as long as it's in the original motherboard.
It's unlocked (not decrypted) when the OS boots, yes. You can optionally enforce (not on Home) other unlock methods, such as PIN before the OS boots.
> I want my FDE to be based on a password or a keyfile, not simply by some code in the motherboard.
That's less secure than TPM.
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#89I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.
Stallman tried to warn us with "tivoization".
Re: Microsoft terminates VeraCrypt account, halting Windows updates
#90Earlier quoted context omitted.
To be fair, the tech industry been holding itself back for decades now too, since lots of people seemingly have somewhat low prices to go from being a FOSS evangelist to wearing a "Microsoft <3 Open Source" t-shirt.
that's just a byproduct of "job creators" holding the keys to a comfortable life over everyones head. i dont think its fair to conflate the tech industries self-owns with microsofts damages. microsoft has for decades poured untold resources and money into capturing everything they possibly could to sustain themselves with honestly what i call cultural and software vendor lock. we're only just now seeing the gaming in…