Live data from Hacker News

Microsoft terminated the account VeraCrypt used to sign Windows drivers

sourceforge.net

91–100 of 526 posts

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#91
post #65

Earlier quoted context omitted.

> No tinfoil needed. That's what Big Tinfoil wants you to believe!

Wait, what?! I was sure that the agenda of Big Tinfoil was to generate FUD so that we buy more tinfoil for our hats. Are you implying their agenda goes even deeper?

But making money at the expense of people is not a Tinfoil conspiracy - it's a factual statement.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#92
post #6

They need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.

Isn't this Microsoft abusing their quasi-monopoly as a consumer PC OS vendor?

If it weren't for the current administration, I'd say it's time for regulatory action.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#93

Earlier quoted context omitted.

Yeah but isn't the point of these certificates to express trust ? The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit. Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a C…

who on planet earth trusts a piece of software because Microsoft signed it?

There are different types of trust, but at the very least with such a signature you can trust that the piece of software is really from Veracrypt and not from a malicious third party.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#95
post #85

Honest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.

It's more or less commonly accepted that its creator got jailed for being an arms dealer.

https://en.wikipedia.org/wiki/Paul_Le_Roux

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#96
post #48

Looks like Linux and some of the BSDs are the only remaining truly open OSes.

Except compulsory age verification in Linux is now becoming a real threat. Some Linux distros are actively against this but many are not seemingly interested in fighting it: CachyOS, Ubuntu, Fedora and others. Age Verification is the thin end of a much bigger wedge in "open" OS's

I thought community projects (as opposed to the corporate Fedora and Ubuntu) are exempt from such laws.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#98
prediction: they are testing the waters. If there is enough outcry they will go "oopsie whoopsie, hehe :3 your account is restored".

If there isn't enough outcry they will go forward and disable more signing keys related to things like torrent clients, VPN software, eject UBO from the edge store etc etc.

Atleast now I'm a bit more certain that VC is indeed safe.

Re: Microsoft terminated the account VeraCrypt used to sign Windows drivers

#100
post #77

Earlier quoted context omitted.

I am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.

Agree. Single point of failure. One developer, one account. Crazy.

How would more than one account help in this scenario, exactly?
Post reply on HN