6 ms·
Getting less and less able to run what we like on our own machines without someone elses permission...
by jbb555 10y ago
Getting less and less able to run what we like on our own machines without someone elses permission...
- bramblerose 10y agoThere is nothing stopping you from running your own drivers, but you either have to turn safe boot off [1], or you have to test-sign the driver [2]. This is a completely reasonable change for 99% of users (because it will stop them from installing a malware driver), and there are well-documented ways around it for the 1% of users that need to side-load drivers. [1] OP, under 'How do I sign drivers during development and testing?' [2] https://msdn.microsoft.com/en-us/windows/hardware/drivers/install/signing-drivers-during-development-and-test--windows-vista-and-later- https://msdn.microsoft.com/en-us/windows/hardware/drivers/in...
- kuschku 10y agoAnd what do open source projects do? The kind that develops ext2 drivers for windows, or pcap, or so on? Does Microsoft pay the costs for the EV certificate for all of those? That’s quite generous of them.
- gtirloni 10y agoI doubt MS will pay the costs for all open source project out there that want to ship signed drivers. Certum seems like a reasonable solution (14 EUR). https://en.sklep.certum.pl/data-safety/code-signing-certificates/open-source-code-signing.html https://en.sklep.certum.pl/data-safety/code-signing-certific...
- deleted 10y ago[deleted]
- Namidairo 10y agoThe 14 EUR Open Source Code Signing product can't be used to sign drivers. It's typically for signing your MSI's and miscellaneous executables before distribution.
- Lan 10y agoI disagree. I think Microsoft's current driver policies are unreasonable. Most end-users don't want to run their PC in testing mode, and will look for an easier way around it. This has a negative effect on free and open-source software. For example, there is software out there that allows you to use Playstation 3 controllers with your PC. In the past, there were pretty much two software solutions for Windows. One driver was unsigned, and the other was signed. Many people used the latter because it was much easier to get working. The problem is that it also installed alongside Chinese malware. Driver signing didn't save anyone there. If anything, it made the issue worse.
- ksk 10y agoSo your complaint as far as I can understand it is - both solutions are imperfect. Well, great ! I do think you're conflating 'reasonable' with 'perfect'.
- Lan 10y agoActually, my complaint is that if you go through the effort of manually disabling driver verification checks at boot time, Microsoft should respect your decision and allow you to persist that decision for that driver, even if you reboot and turn verification back on. They don't, and instead give you an all or nothing approach, with the nothing approach being a hassle and leaving a permanent watermark in the bottom right corner of your display.
- ksk 10y ago> Microsoft should respect your decision and allow you to persist that decision for that driver, even if you reboot and turn verification back on. If you have a whitelist, then malware authors would ship a primary driver that is signed and "clean". This clean driver just changes the whitelist so other malware can be executed without signature checks. I would suggest you first model the threat, model your response and analyze the different approaches.
- sievebrain 10y agoFree and open source software can still be signed.
- pjc50 10y agoI've been writing https://github.com/pjc50/pjc50.github.io/blob/master/pentagram-control.md https://github.com/pjc50/pjc50.github.io/blob/master/pentagr... on this phenomenon.