23 ms·
Microsoft terminated the account VeraCrypt used to sign Windows drivers
- teekert 6mo agoI'm sorry, is this some sort of Windows joke that I'm too Linux to understand?
- account42 6mo agoLinux isn't inherently safe from the signed boot chain mindset either if you run a mainstream distribution.
- dizhn 6mo agoMicrosoft disabled the developer's certificate so no windows releases can be made.
- jonathanstrange 6mo agoAs someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established? Are there some ways to combat such decisions legally?
- politelemon 6mo agoThis is a concern and risk that has realised itself multiple times over the past decades. There have been multiple stories linked to multiple developers in the past. If you publish to any closed platform including ios, mac, win, android, this is the risk you run and a condition of operating you will need to accept.
- account42 6mo agoFor open source user space programs, another option is to just not sign your software. Will annoy your users, some of which will annoy you in turn, but many are already trained to ignore the scary warnings Windows shows in that case and more will continue to be trained until more reasonable options exist.
- shelled 6mo agoRealistically speaking - anything could be a reason. A shakedown or blocking based on some "nudge" (this might come across as tin-foiled though). Some flag/trip-wires going wrong, more worryingly due to a bug/false alarm - and this is more worrying because in this case semi-incompetent large orgs like MSFT find it really hard to accept it, fix, and move on. Some change in OP's account that either they don't see or haven't realised - some edge case, you never know. And of course, it doesn't affect their earnings and there are no consequence, or significant, so they won't care and won't respond or tell what went wrong. Can one move legally? Sure. But then it effectively is a combo of who blinks first and who can hold their breath longer.
- technion 6mo agoThere's more to it. Signed desktop software can be signed by any CA. Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines. In general this isn't your problem.
- raxxorraxor 6mo agoSpeculation as well and highly unlikely. Microsoft drivers can very well BSOD your machine as well, not a significant or convincing threat scenario and certainly not something that lead to certificate revocation of driver developers. There is zero quality control or review by Microsoft here. Not for their own products and not for third party ones.
- steve1977 6mo agoExhibit A: https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_ou...
- fluoridation 6mo agoThat's not entirely true. Certain classes of signing keys require driver developers to put their driver through a test battery and submit the results to Microsoft.
- rkagerer 6mo agoI wish Microsoft expanded and built on that model, instead of moves like firing swarthes of their QA staff. It could have grown into a massive, self-service testing playground where any developer could submit their product and put it through an arsenal of basic, automated evaluations (e. does uninstall leave tidbits behind?), with paid upgrades to more tailored services. They could even publish scores to help consumers coarsely compare workmanship across different vendors, and encourage an emphasis on quality across the whole ecosystem. Instead they decided to just become overpaid bouncers who take your money, check your ID, and don't even bother about what you bring through the door.
- actionfromafar 6mo agoYou just have to start living like they do in Russia and comply in advance. Don't do anything "interesting", no encryption, or if you do, make sure you leave breadcrumbs, scratch that, a bread trail for them to easily get access to customer data. An Oracle or Sharepoint integration maybe?
- electroly 6mo agoPerhaps not legally, but technically, you have an option: don't use the Microsoft Store. This isn't as wild a suggestion as it may seem to non-Windows users: the store is barely used by Windows users. You can get your own code signing certificate from a public CA, sign your own installer, and post it on your website. This is still the primary way that Windows software is distributed. Microsoft does not have a hand in any part of it; they can't cancel anything. Their only role is including the public CA in their root certificate store. If you're not shipping a kernel driver, you don't need Microsoft's permission for anything. You can still ship an .msix installer which is the same technology used by the Store. I recently de-listed my app in the store and closed my Microsoft developer account. I was wrong for having bothered with it; just a waste of my time for no benefit. Stick to your own deployment.
- ComputerGuru 6mo agoIt’s become neigh impossible to get your own code signing cert these days. The 2025 update from the CA forum required code signing certs to be short lived (no more three or five year certs) and stored exclusively on an HSM. As a result, most companies cross-signing these certs have moved to a subscription PaaS model where you are issued a cert but never receive custody of it, and perform signing via their APIs, and are at their mercy should they decide to block your account. Anyway, even if you could get your own cert it would be same thing: MS could revoke or blacklist your indicate cert (though usually the grounds for doing so are much less shaky than your account being suspended for vague “tos violations”)
- electroly 6mo agoI was afraid of the HSM at first but for an open source developer (rather than a big company) I found it wasn't a big deal. I can't sign in GitHub Actions and I have a USB stick that lights up when I sign releases, but it hasn't been a blocker. I got mine from Sectigo Store. This isn't hypothetical, I really did it, I've got the HSM, it works. It wasn't difficult. It just cost some money and a little bit of time. "Nigh impossible" is a tremendous exaggeration. I'll concede "annoying and expensive" perhaps. If you've got the money, you can get the HSM. You don't have to re-buy the HSM when you renew your certificate. The Microsoft Store account was painful to set up, I'll note. My developer account had also been cancelled by Microsoft for unknown reasons, and I ultimately had to set up a brand new one. New email, new name. My new account has my middle initial because I couldn't clash with the existing, closed account. My first and last name alone are banished forever from the store. The "same thing", as you concede, isn't the same thing. Quantity has a quality of its own: one happens all the time and we're reading an article about it happening right now. In the comments there's another prominent maintainer who it happened to, and it happened to me personally! That's three right here! The other happens so infrequently that people in this same HN thread are complaining that it isn't happening enough. Can you find an example that's like Veracrypt and WireGuard? In practice, it seems they rarely do this, even when they should. You can actually view the list under "Manage computer certificates" > "Untrusted Certificates." On my computer the entire list is 20 certificates. I'm standing by my suggestion, 100%. These aren't equivalent risks at all.
- lossyalgo 6mo agoAccording to this: https://x.com/EdgeSecurity/status/2041872931576299888 https://x.com/EdgeSecurity/status/2041872931576299888 > ...it seems like they instituted an identity verification policy, didn't notify me about it, and then I guess they suspended accounts who didn't do the verification. So, make sure you verify your account? Check spam folder regularly? Log in via web interface at least once a year?
- Gareth321 6mo agoWe can still install, right? It just comes up with a scary warning. Still not great but at least we aren't locked out.
- Strom 6mo agoYou can, but it's more than a warning. VeraCrypt has a signed kernel driver, which has higher requirements. You'll need to boot into a special Windows mode and disable Driver Signature Enforcement.
- HauntingPin 6mo agoAfaict, you can't disable driver signature enforcement permanently without disabling secure boot.
- nslsm 6mo agoYou also get a huge watermark that says "Test Mode" that takes up the entire screen (not kidding)
- DHowett 6mo agoThree lines of text in 12-point font in the corner which can be covered by a window is hardly “the entire screen.”
- nslsm 6mo agoThey changed it recently. https://learn-attachment.microsoft.com/api/attachments/f8eac6dc-99c4-446c-87b8-5ab05feada47?platform=QnA https://learn-attachment.microsoft.com/api/attachments/f8eac...
- anfilt 6mo agoNot the OP you responded too, but what the hell! I have not really used windows in a while but that's absurd. That text is massive just for an unsigned driver.
- ErroneousBosh 6mo agoJesus, sourceforge is still on the go?
- SXX 6mo agoMight be it even not using all your code to train AI. Or at least not asking your explicit permission to do it.
- karel-3d 6mo agosourceforge was always very scummy, I think they would definitely use the code for that if they could
- mbreese 6mo agoIt wasn’t always scummy… but there was a definite shift after they got bought. It’s kept getting worse since then. Then again, this was something like 20 years ago. Back then, Sourceforge was something closer to GitHub today. It was the de facto public source repository. You could even get an on-premise version, IIRC. Actually, this is sounding a lot like GitHub these days… not sure what that means.
- ErroneousBosh 6mo agoAs I've said elsewhere, freshmeat.net was better :-)
- mbreese 6mo agoFor project discovery, definitely -- but not as a source code repository. Wow, we're dating ourselves on this, but I remember when it was a big deal that SF.net added SVN support. They apparently didn't turn off CVS until 2017!
- ErroneousBosh 6mo ago
- firen777 6mo agoIt's like LibreOffice all over again: https://www.neowin.net/news/microsoft-bans-libreoffice-developers-account-without-warning-rejects-appeal/ https://www.neowin.net/news/microsoft-bans-libreoffice-devel...
- SeanDav 6mo agoThis is worrying on many levels. So Microsoft force you to create an account to use Windows and then they reserve the right to block you from your own account, thereby potentially making you lose access to all your OWN data. This is crazy and yet another reason to stop using Windows as soon as possible.
- xorcist 6mo agoIt's not your own data anymore if you gave it away.
- criddell 6mo agoOr create the account but don't use Microsoft services.
- jerf 6mo agoI know it's not what people want to hear but my response to a lot of the comments here is just a general, I agree, it's time to stop using Windows. They won't let you secure your drive the way you want. They won't let you secure your network the way you want (per the top-level comment about Wireguard). In so doing they are demonstrating not just that they can stop you from running these particular programs but that they are very likely going to exert this control on the entire product category going forward, and I see little reason to believe they will stop there. These are not minor issues; these are fundamental to the safety, security, and functionality of your machine. This indicates that Microsoft will continue to compromise the safety, security, and functionality of your machine going forward to their benefit as they see fit. This is intolerable for many, many use cases. I think it is becoming clear that Microsoft no longer considers Windows users to be their customers any more. Despite the fact that people do in fact pay for Windows, Microsoft has shifted from largely supporting their customers to out-and-out exploiting their customers. (Granted a certain amount of exploitation has been around for a long time, but things like the best backwards compatibility in the industry showed their support, as well.) I suspect this is the result of a lot of internal changes (not one big one) but I also see no particular reason at the moment to expect this to change. To my eyes both the first and second derivative is heading in the direction of more exploitation. More treating users like a cattle field and less like customers. When new features or work is being proposed at Microsoft, it is clear that it is being analyzed entirely in terms of how it can benefit Microsoft and users are not at the table. No amount of wishing this wasn't so is going to change anything. No amount of complaining about how hard it is to get off of Windows is going to change anything; indeed at this point you're just signalling to Microsoft that they are correct and they can treat you this way and there's nothing you will do about it for a long time.
- pogue 6mo agoThey need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.
- CR1337 6mo agoI blew the lid on X today: https://x.com/i/status/2041698657368703484 https://x.com/i/status/2041698657368703484
- bombcar 6mo agoThe (new?) X link made me think for a moment you got the username @i
- aaronmdjones 6mo agoThe website formerly known as Twitter has never cared about the username part of the URI; it only looks at the status number and will redirect you to the canonical version if it wasn't.
- yegle 6mo agoThe /i/ links are not new, but they used to be for internal (?) links e.g. ads.
- malfist 6mo ago[flagged]
- john_strinlai 6mo ago1) its weird to disparage someone that is trying to help, no matter how small or large of an effect you think the help will have 2) they got 120,000 views, 400 retweets, and 1.7k likes in ~12 hours. that is a good amount of awareness. certainly more than i would get from a tweet. certainly more help than whatever you are doing here.
- ninjagoo 6mo agoLooks like Linux and some of the BSDs are the only remaining truly open OSes.
- krylon 6mo agoTrue, however, that has been the case for quite a while. This particular incident doesn't change that, except for the VeraCrypt developer, who is in a crappy situation now (not just regarding VeraCrypt, he mentions he was using the certificate for his main job as well, so this sucks a lot for him).
- sph 6mo agoWell, of course. Have the other commercial offerings every been "truly open OSes"?
- Aachen 6mo agoSo far I haven't had much concrete reason for my family to switch away from Windows. The updates maybe, needing to pay for a new license and the UI changes are like pulling the chair out from under them, especially as they get older (Windows 7 was hard for my grandma, thankfully they left 10 mostly alone but 11 is quite different again so she's currently staying on 10 — not that her hardware supports 11 anyway but that's fixable), but it's either learning the new Windows UI, let's say ten storypoints of newness, or learning some Linux desktop environment, even if it's Mint which is similar to 7/XP it's not quite the same either and probably like 15 storypoints at minimum, even if then you're done for much longer But if OSes are being locked down and software has trouble distributing security updates through official repositories for Windows... that's a good reason to finally make the switch. Same as why my family is on Android: I can install f-droid, disable the google store, and don't have to worry about them installing malware / spyware / adware There's different degrees of openness. Android till 2026 was an acceptable compromise (let's see how it goed forwards). Windows is also on the decline with their account policy, not sure about this certificate revocation thing (thankfully haven't had to deal with it yet; I'm not a user myself) but it sounds like they're moving to a walled garden also When the degree changes and gets even less open, yeah you can say "well of course, they were never truly open, they're commercial" but it's still a change and might lead people to alter their choices
- deleted 6mo ago[deleted]
- nixpulvis 6mo agoWe need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.
- PunchyHamster 6mo agoJust add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway
- mr_mitm 6mo agoWhat would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.
- Eldt 6mo agoMisplaced trustworthiness?
- duskdozer 6mo agoIs it some entirely different process than providing hashes and a GPG signature?
- mr_mitm 6mo agoWell, yes. Just look at OP and Jason struggling to get their code signed.
- sidewndr46 6mo agoMicrosoft signed the Crowdstrike updates. I don't think a CA signing a piece of malware is a realistic thing to be concerned about.
- megous 6mo agoOnly signal is that whoever is in the subject DN (highly) probably signed the code. There's 0 signal about trustworthiness of the code in the signature. Thrustworthiness signal is in the behavior/reputation of the signer. Pretty sure there were historically a lot of apps that stole peoples contact lists and were signed properly. Certainly in the Android world.
- speedgoose 6mo agoIt's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.
- subscribed 6mo agoProbably not French though, give how hostile it appears to be to encryption/security related projects (GrapheneOS had a good arguments re: that)
- kijin 6mo agoThe author is now based in Japan, and even owns a veracrypt.jp domain. Meanwhile, the old veracrypt.fr domain redirects to veracrypt.io. Seems rather clear that he doesn't want French jurisdiction.
- orbital-decay 6mo agoThat's what VeraCrypt is, a fork of the original TrueCrypt after all drama, security doubts, and eventual discontinuation. It took a long time and two independent audits to establish trust in it.
- repelsteeltje 6mo agoYeah but isn't the point of these certificates to express trust? The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit. Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a CA and as an organization.
- sidewndr46 6mo agowho on planet earth trusts a piece of software because Microsoft signed it?
- RandomGerm4n 6mo agoThat's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game no longer launches on a computer using a driver with that certificate. Microsoft however does not do this and malware developers can then simply use the certificates for their own purposes. So all this nonsense is basically just a restriction on regular users and honest developers while the “bad guys” can get around it.
- vaginaphobic 6mo ago[dead]
- redox99 6mo agoThat's kind of crazy. Why doesn't Microsoft revoke such certs such that you can't sign new software with it?
- steve1977 6mo agoBecause it's mostly just performative.
- Deathmax 6mo agoMicrosoft has been taking steps to mitigate the leaked code signing certificate problem. On the driver side of things, new versions of Windows no longer trust the cross-signed certs, so you must submit your driver to Microsoft to validate and sign, so no private key to go missing. https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-driver-security-removing-trust-for-the-cross-signed-driver-pro/4504818 https://techcommunity.microsoft.com/blog/windows-itpro-blog/... On the regular Authenticode side of things, the new CA/B Forum rules have prohibited storing new private keys outside of hardware modules for a while now, so eventually you won't be able to find a leaked private key for code signing that would still be valid.
- shelled 6mo agoI am somewhat also concerned that this software was still being distributed on SourceForge.
- frizlab 6mo agoI don’t even understand how SourceForge still exists!
- reddalo 6mo agoYes, I stopped using SourceForge after they started tampering with installers to put adware inside of them. It's a bit worrying that a sensitive app such as VeraCrypt is still distributed there.
- poizan42 6mo agoThat was 11 years ago, under DHI Group though. I don't think Slashdot Media have been up to the same shady stuff.
- Joe_Cool 6mo agoJust shows how quickly and thoroughly those stupid suits managed to destroy its reputation. Guess they love burning money or really needed those tax writeoffs.
- deleted 6mo ago[deleted]
- Pay08 6mo agoWhy?
- qwertox 6mo ago~2015, "DevShare". They wrapped open-source software downloads with opt-out adware and PUPs (potentially unwanted programs), without the original developers' consent in some cases. They took over abandoned/unmaintained projects (like GIMP for Windows, VLC, etc.) and replaced the original download with their adware-wrapped version.
- _s_a_m_ 6mo agoMicrosoft doing everything in their power to be assholes, as always
- krylon 6mo agoAs much as I like bashing Microsoft, never underestimate people's capacity for incompetence, especially where large organizations are involved. I don't see how they would gain anything from this move.
- cm2187 6mo agoIt doesn’t help that they do that sort of shits AND mandate a microsoft account for logging in to windows. Also how much trust can you have that if you move your business to azure they will not randomly kill it. Incompetence or malice, almost doesn’t matter to the average user.
- krylon 6mo agoThe outcome is the same, yes. With incompetence, there is at least a glimmer of hope things will get rectified. But you are correct, trust is destroyed this way, and it doesn't look like Microsoft cares much.
- deleted 6mo ago[deleted]
- account42 6mo agoAnd never underestimate the capacity of useful idiots for defending malicious actors.
- saidnooneever 6mo agomaybe an old vulnerable signed driver can be used to load the new version :D. on a more seirous note, i think contact with a person at MS, likely via socials triggering that, might help here. It all depends on the reason for the ban/block/cancel. if they had a reason other than 'oops mistake' its likely just going to remain in place. (sadly, that is how MS is. if you care for privacy maybe go to BSD)
- zx2c4 6mo agoThis is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't freak out!) In that case, Microsoft would have my hands entirely tied. If anybody within Microsoft is able to do something, please contact me -- jason at zx2c4 dot com.
- gib444 6mo agoY'all need to form an alliance or something, get some press coverage (wireguard, veracrypt, libreoffice)
- duskdozer 6mo agoTrue, but really even if it gets resolved for them it should basically be a huge warning sign to everybody. Projects like those might get reinstated but it would only be because of how big they are that it would matter. Any person or small or 'undesirable' project would not get the same resolution.
- teruakohatu 6mo agoI am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.
- miroljub 6mo agoMaybe time for a custom license that would require M$ to sign up for special T&Cs if they want to use this software? Who cares if it's OSI-approved or not, a line saying "M$, Google, and the like need written permission for every use case" would help to make those leeches honest. Just learn from the JSLint example.
- 6mo ago
- tomgag 6mo agoSorry to hear about this turn of events, but it was pretty much to be expected given the way the world is turning, and Microsoft being Microsoft. Switch to Linux if you can, and come give Shufflecake a try ;) https://shufflecake.net/ https://shufflecake.net/
- LWIRVoltage 6mo ago.... This deserves it's own posts , on HN, just for awareness- Aside from https://web.archive.org/web/20250914062843/https://portswigger.net/daily-swig/russian-doll-steganography-allows-users-to-mask-covert-drives https://web.archive.org/web/20250914062843/https://portswigg... , there haven't been really many goes at going for plausible deniability with modern systems, and I see the segment about a Hidden OS feature in work as well. Hoping this succeeds. Funny, eventually Shufflecake, after it gets fully capable on Linux, might have to look at making versions for Windows and Mac
- 8cvor6j844qw_d6 6mo agoSeeing this kind of friction makes me more confident in VeraCrypt. The tools that never seem to run into trouble with platform gatekeepers are the ones I'd worry about.
- Pay08 6mo agoThat seems like a very nonsensical stance.
- andrewmcwatters 6mo ago[dead]
- pocksuppet 6mo agoWell look at something like ANOM. The FBI encouraged its use. Because it was run by the FBI and they could see all the private messages. If Veracrypt was a honeypot, the powers that be would go out of their way to make it as easy to use as possible. They'd instantly sack whoever made this decision, and reverse it.
- Pay08 6mo agoSo is coreutils a honeypot?
- baobabKoodaa 6mo agoThe biggest risk in encryption software is that you lose access to your data. You seem to be ignoring that risk completely and focusing on something else entirely.
- dboreham 6mo agoI don't think you would loose access. You can always recover data on an open platform such as Linux.
- bilekas 6mo agoAnd yet another example of companies turning actively hostile against their users. The burden of usage/access is now solely on the customers and the feeling is that regular customers are just a nuisance to be ignored.
- avaer 6mo agoForced software signing should be illegal.
- Pay08 6mo agoIt's not forced, especially for normal software, you just get a popup. It's a bit of a pain to disable the requirement for drivers, though.
- baobabKoodaa 6mo agoI don't think you can install VeraCrypt, at least for system encryption, unless the installer is signed
- Pay08 6mo agoAccording to further up the thread, you can if you disable secureboot.
- pocksuppet 6mo agoAnd you mess with your boot.ini and ignore that half your screen is taken up by a TEST MODE banner. Buy a screen twice as big and tape over half of it, I guess.
- kwar13 6mo agovery much sounds like microsoft
- Topfi 6mo agoHonest question, did we ever get an answer what was the cause for the sudden change from the original Truecrypt developer? Even if one doesn't want to maintain that project for purely private reasons, recommending Bitlocker as the drop-in-replacement always made it smell fishy to me.
- abcd_f 6mo agoIt's more or less commonly accepted that its creator got jailed for being an arms dealer. https://en.wikipedia.org/wiki/Paul_Le_Roux https://en.wikipedia.org/wiki/Paul_Le_Roux
- Topfi 6mo agoI knew the speculation on him being involved in some capacity, but as the wiki page states, this was never confirmed in any substantial way. More importantly, if development seized with no public comment, that would be one thing and may strengthen the "he got arrested" theory. However, there was some final communication, specific recommendations to rely on Bitlocker of all things, a new version of Truecrypt was released solely for decrypting existing disks and then the web page was removed, including a flag set on robots.txt to ensure it wouldn't appear on archive.org. All this concurrent to a crowd funded source code audit that, in the end, did not find any server issues or backdoors (I recall some speculation back in the day, that either known code quality issues or an intentional backdoor could have caused the exodus). That all makes it hard to link this to an arrest of the main developer, though I dislike speculation without any hard evidence and if there is no new information, I'll keep this filed under "there is no answer".
- Izmaki 6mo agoI always believed that rather than publicly stating that they were about to be arrested or worse, which may alert regular, non-tech-savy people, he sent a hidden message in the arguably horrendous recommendation of replacing his tool with BitLocker. I think he was trying to scream “Run!” without actually screaming “run”.
- 6mo ago
- shevy-java 6mo agoThis is always a problem when big mega-corporations are involved, be it Google or Microsoft. They want to control the platform. We really need viable solutions. I have been using Linux since +21 years or so, so it does not affect me personally, but I think Linux needs to become really a LOT more accessible to normal people. And it really has not (on the desktop); all the various "improvements" on GNOME3 or KDE are basically pointless, they have not solved the underlying problem. Ideally problems should be auto-resolvable. If someone wants to use the proprietary nvidia driver, that should be a single click - on ALL Linux distributions. Instead you see some distributions have their own ad-hoc solution and other distributions have no easy solution (for simple people).
- SV_BubbleTime 6mo agoI will continue to suppose that the “real issue” with Linux is that the people drawn to developing it will not work well with others and continue year after year to waste time and duplication of effort on five decent, and ten thousand pointless distributions. Whatever reason for this refusal / inability / choice to not contribute but rather re-create is on the reader to assume. There is very little effort put into real progress as you point out. Sure, tons of work to move from x11 to Wayland, cool, only the developers give a shit… where is Office/365 that would make daily driving actually viable? While WINE is impressive, it seems the only real progress for anything past Windows 7 is on paid versions of which there are at least three competing options. Linux Desktop progress is slow because there it’s thousands of floundering side-projects without a goal of actually pulling normal users in.
- no_time 6mo agoprediction: they are testing the waters. If there is enough outcry they will go "oopsie whoopsie, hehe :3 your account is restored". If there isn't enough outcry they will go forward and disable more signing keys related to things like torrent clients, VPN software, eject UBO from the edge store etc etc. Atleast now I'm a bit more certain that VC is indeed safe.
- superxpro12 6mo agoThey've finally sprung their enshittification trap. Their move into "open source" was never of friendly origin. It was a business move, plain and simple. And now they're locking down Window OS, hard. Expect github and vscode to follow.
- trinsic2 6mo agoI left GitHub for GitLab because i knew this was coming.
- hernanhumana 6mo agocool project
- 0xCE0 6mo agoLinux is the only hope at this point for the future of computing. Windows and macOS are just too risky to do any business with. Waste of all resources.
- cguess 6mo agoand yet... still unusable by the mass majority of people.
- teekert 6mo agoMy kids grew up on Gnome essentially, I can tell you Win11 is a lot more confusing to them, not just because because they grew up on Gnome, there is just so much more ... stuff. And notifications and flashy things and news and weather apps and they all want your attention. Gnome is much more iPadOS like (minus that horrible concoction called the App Store). Sure, if you're all in on MS365 (like all schools here in the Netherlands), Windows may be somewhat more handy with its native apps and all your stuff there with a single log-in.
- cguess 6mo agoAnd someone once raised their kids speaking Klingon, that isn't a good excuse on why it's a language others should use. For the vast majority of people MS365 is a requirement, but really the issue is that even minor fixes require the command line on Linux and that makes it unusable.
- teekert 6mo agoI guess it means that even when something is (arguably) objectively more simple, people still won't bdge just because they don't want change. They don't want to learn new things. I myself am quite different. I have thoroughly had it with my current iPhone and am eyeballing /e/OS, before that I really started to find Android boring, before that Windows mobile (the nice one with the cards). I switch Gnome, KDE, some other DE (now getting ready to try Niri) every year or 2. I don't get the struggle, for me a new env is like a present (even though I normally hate presents). So much niceness to explore, so much to optimize. I love it. But I'm also one of those guys that reads the oven manual and tries all functions in week 1. I'm not weird, all you people are weird.
- trashface 6mo agoHope this is resolved. I guess I could run linux in a VM and mount volumes there, but this is getting a bit dicey. But Win 10 is my last windows anyway.
- folbec 6mo agoI would not be surprised if it was some sort of AI driven mistake. Some guy somewhere deciding to delegate threat assessment to Copilot or some other automated tool.
- john_strinlai 6mo agoi would bet a years salaray that you are correct. copilot or some automated process. and then the message is automated with an automated appeal-denial flow. conspiracy theories are fun and all, but 99.99% of the time it is just incompetence, miscommunication, etc.
- mapontosevenths 6mo agoAny chance this is the issue? https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-driver-security-removing-trust-for-the-cross-signed-driver-pro/4504818 https://techcommunity.microsoft.com/blog/windows-itpro-blog/...
- HumanOstrich 6mo agoFrom TFA: "I have encountered some challenges but the most serious one is that Microsoft terminated the account I have used for years to sign Windows drivers and the bootloader."
- mapontosevenths 6mo agoYeah, and the first comment beneath that mentions that the most recent version is signed with the "2011 CA" that the article I link to discusses being deprecated. My guess was that he got caught up in some house-cleaning. My theory being that he's still signing his code the way malware authors also do and got flagged by some automated review that's meant to force him to go get WHCP certified or whatever the new route is.
- HumanOstrich 6mo agoThe article you linked says the change is rolling out in April in evaluation mode. And if it were related to some kind of scan and malware flagging, the cert would have been revoked. It is not.
- mapontosevenths 6mo agoFair enough. Thanks for weighing in.
- swordsith 6mo agoif michalesoft wants to take away our ability to sign drivers, they will find there is more than enough vulnerable easily exploited drivers we can use that are pre-signed online. Thank you micosawft!
- HumanOstrich 6mo agoAre you having a stroke?
- c0balt 6mo agoMost likely just intentionally misspelling the name in the spirit of calling them Microslop.
- deltoidmaximus 6mo agoAnd perhaps the time they sued a kid named Mike Rowe for having a website mikerowesoft.com
- qingcharles 6mo agoI think it's a reference to Michaelsoft Binbows :) https://alf-s-room.com/etc/nandarou/binbows/binbows_english.htm https://alf-s-room.com/etc/nandarou/binbows/binbows_english.... https://www.youtube.com/watch?v=QRIklga9IBQ https://www.youtube.com/watch?v=QRIklga9IBQ
- baobabKoodaa 6mo agoCan someone please explain the implications for current Windows users of VeraCrypt?
- ratg13 6mo agoNo new features, no security patches.
- baobabKoodaa 6mo agoAnyone here who could reach out to specific persons inside Microsoft who could fix this?
- satai 6mo agoMicrosoft can't be trusted. Never was, isn't and I guess won't be.
- not_a9 6mo agohttps://community.osr.com/t/locked-out-of-microsoft-partner-center-driver-submission-page/60061 https://community.osr.com/t/locked-out-of-microsoft-partner-... Could be a related issue to this? Maybe Microsoft just doesn’t want driver developers for whatever reason.
- superxpro12 6mo agoits my computer. its my os. i own it. I paid my money and bought the program. not them. I am free to install whatever software and modify whatever kernel components as i see fit. I am so sick and tired of the continued erosion of the ownership model. I dont want to rent anything. But corporations see it as an avenue to increase revenue. We pay more, for less. What else is new.
- fsflover 6mo agoSo why don't you stop using the OS that has a completely different approach to computing?
- chaostheory 6mo agoIt’s time to switch to Linux or another open OS.
- altairprime 6mo agoPresumably it’s part of their commitment to kill kernel patching in Windows, to prevent another Worldwide Enterprise Windows Outage Caused By A Buggy Vendor DLL event.
- Avamander 6mo agoMost certainly it's related to this: https://techcommunity.microsoft.com/blog/hardware-dev-center/action-required-account-verification-for-windows-hardware-program-begins-october/4455452 https://techcommunity.microsoft.com/blog/hardware-dev-center...
- steve1977 6mo agoIf only there was a way to sign software and not depend on a centralized authority, something like a... web of trust? (and yes I know, you'd need to have the option to have "your" (haha...) OS trust it of course)
- Hizonner 6mo agoThis highlights the fact that not only is supporting Windows dangerous to your project, but using Windows is dangerous to your security.
- Tsarp 6mo agoFor folks looking for a much simpler single binary alternative. https://github.com/srv1n/kurpod https://github.com/srv1n/kurpod
- layer8 6mo agoThis is not a replacement, as it has no native file system integration, only a web interface.
- hereme888 6mo agoBesides Veracrypt, are there any real alternatives to Bitlocker for total drive encryption in Windows?
- Havoc 6mo agoMicrosoft continues to push for year of the Linux desktop
- unethical_ban 6mo agoI run a dual boot of windows and am currently dauly-driving CachyOS quite happily. I've been playing some Crimson desert and got some occasional crashes... But any other game I have has run smoothly. Their GUI tools for package management are thin wrappers on CLI tools, but are enough hand-holding that most people should navigate it fine. More devices worked out of the box for my with Linux than Windows. Just like if you haven't tried AI in a year and have mocked it, you need to try it again. Of you haven't tried Linux desktop in a few years, you need to try again. CachyOS really does seem to handle the driver installs and gaming compatibility well.
- raggi 6mo agoCachy pushed a Limine update last weekend without any testing. It broke everyone with secure boot signing. Head proton versions are great, but games tend to turn into a laggy mess after a couple of hours and need regular restarts. It's decent, but it's not all roses at all, and I wouldn't inflict it on non-techies yet.
- unethical_ban 6mo agoAh, I disabled secure boot assuming it's pointless and wouldn't work with arch and dual booting anyway. Maybe I have more to learn. Perhaps cachyos should maintain LTS metapackages for more than just the kernel. Video drivers, boot managers and whatnot. For a "non-gamer" I would probably keep them on Fedora or even Debian.
- cynicalsecurity 6mo agoIf you use Veracrypt on Windows then you have no idea what you are doing. Windows is not safe. Use Linux only.
- HackerThemAll 6mo agoI would love to switch long time ago, but I make money on Windows enterprise customers, using specific Windows tools that have no reasonable Linux counterparts. I'll throw my Windows laptop out of a (pun intended) window on the exact second I'll secure viable and sustainable income using Linux. I know it can be done, but so far it's outside of my circles.
- Izmaki 6mo agoReminds me of when users of TrueCrypt were urged to just install BitLocker instead. Sus AF.
- LWIRVoltage 6mo agoWhat sucks about this, is due to implementation,Windows is the only way to achieve some stuff in Veracrypt. For example: doing full system partition encryption, and the Hidden OS install that only Veracrypt can do- requires Windows with the computer set to MBR rather than UEFU. I had hoped we'd see more of the plausible deniability tech at the OS level But aside from one or two experimental attempts, also presented at BlackHat https://web.archive.org/web/20250914062843/https://portswigger.net/daily-swig/russian-doll-steganography-allows-users-to-mask-covert-drives https://web.archive.org/web/20250914062843/https://portswigg... - the consumer has nearly lost access to high end plausible deniability
- Tepix 6mo ago> Windows is the only way to achieve some stuff in Veracrypt On the other hand, if you get rid of Windows you don't even need Veracrypt.
- newsoftheday 6mo agoFirst I was surprised to read the Veracrypt maintainers could be in this situation, then read the top comment where Wireguard maintainers are too (unless I misunderstood). Is this some malicious new program inside Microsoft to try and shutdown open source projects so they can push Windows products and solutions more?
- gzread 6mo agoYes.
- NewsaHackO 6mo agoIt feels more like an automated block due to uncharacteristical increase in download activity. Something that it seems more and more companies are taking seriously is the cottage industry of scams involving less technically savvy downloading apps online and getting their information stolen. The motivation for this is probably the same as Google stopping side loading. Take that as you want.
- subscribed 6mo agoAnd how would blocking the devs ability to sign the new version stop the spread of the already downloaded and still available old version? I think you forgot we're talking about the kernel drivers specifically - normal scammers don't need that, they use AnyConnect downloaded from Chrome. I think you also forgot to read it all and missed that it was supposedly some deanonymisation (ID verification) process that kicked it off, and missed that the dev has immediately verified themselves but then we're told they need to wait 2 months to wait. Because. It's not an automated process at this point.
- trowaway2 6mo ago[dead]
- lofaszvanitt 6mo agoWhat about the guy who originally created it. Paul Le Roux, the criminal mastermind? That's a wild story :D.
- pjdesno 6mo agoInteresting. My only experience with Veracrypt is via a law firm I was consulting with, who used it to protect some files they were sharing with me. Law firm and their end client are both big, prestigious companies.
- surcap526 6mo ago[dead]
- idolofdust 6mo agoGet off Windows right now. The newest frontier AI models can easily find 0-days in all major software stacks, while the two biggest open source security tools on Windows can’t even ship patches.
- 1970-01-01 6mo agoWhy is there no simple workaround for this? Why is it dead in the water and why can't we use another mechanism to verify the update files with SHA1? It's all been done before [1]. This would be an improvement, as it enables the project to continue working without any handcuffed relationship to Microsoft. [1] https://github.com/HyperSine/Windows10-CustomKernelSigners https://github.com/HyperSine/Windows10-CustomKernelSigners
- Ms-J 6mo agoPosted this earlier from a throwaway since my account wasn't able to reply for some odd reason and it was marked as dead: Hello Jason! I want to first thank you for all of your hard work developing Wireguard. If I can find someone who is willing to put their name on it to help I definitely will, the problem is the spy agencies don't want your project to exist. It makes it harder to put resources to this. I've worked in security departments of certain companies and saw everything you could imagine. Same for Mounir over at Veracrypt. Both of you are developing some of the most important software that exists today. Keep doing what you are doing by keeping everything in the open. User trust almost doesn't exist for these type of projects. Any hint of an issue would wipe that out in seconds. This leads me to one question I do have for you zx2c4: Why does Wireguard attempt to contact your servers and auto update on Android with no toggle to turn this off? It's a threat to everyone. Maybe it also does this on other platforms but I haven't tested them all. I can think of reasons as to why you did this, none nefarious, but still it would be nice if you included that option so I don't have to patch each update to turn this off. Thanks.
- ChrisArchitect 6mo agoUpdate from Scott Hanselman: > Hey I love dumping on my company as much as the next guy, because Microsoft does some dumb stuff, but sometimes it's just check emails and verify your accounts. Not every "WTF micro$oft" moment is a slam dunk. I've emailed VeraCrypt personally and we'll get him unblocked. I've already talked to Jason at WireGuard. Not everything is a conspiracy, sometimes it's literally paperwork. (https://x.com/shanselman/status/2041977121686585396 https://x.com/shanselman/status/2041977121686585396 https://xcancel.com/shanselman/status/2041977121686585396 https://xcancel.com/shanselman/status/2041977121686585396)
- francosimon 6mo agoVLayer (my project) scans healthcare codebases for HIPAA compliance issues before they reach production. One thing I learned building it: developers rarely think about encryption until it's too late. Tools like VeraCrypt solve the "data at rest" problem, but the bigger issue in healthcare software is unencrypted data in logs and API responses — stuff that's much harder to audit manually.
- feyman_r 6mo agoUpdate from a VP at Microsoft: https://x.com/shanselman/status/2041977121686585396?s=46 https://x.com/shanselman/status/2041977121686585396?s=46
- bilekas 6mo agoAmazing that their processes failed and didn't work, so the VP lashes out at everyone calling them out for it. It's not like Microslop isn't a huge organization that is the critical component here. Extremely unprofessional response, I'll reiterate, they see regular users as a nuisance.
- j16sdiz 6mo agoI guess the real problem is, everybody's inbox is overwhelmed with useless junk. Expect someone read and follow instructions in email are not that realistic anymore
- donmcronald 6mo ago“Action Required” followed by the shittiest, least detailed, most ambiguous instructions on the planet is a Microslop staple. It’s exhilarating to get a couple of them in the same week. The ones that tell you there’s a problem with your MS365 subscription, but don’t tell you which one are an especially exciting challenge to deal with. Bonus points if they warn about “possible data deletion” without specifying what.
- deltoidmaximus 6mo ago> The ones that tell you there’s a problem with your MS365 subscription, but don’t tell you which one are an especially exciting challenge to deal with. Bonus points if they warn about “possible data deletion” without specifying what. These are real? I get these in my spam box all the time and they have all the hallmarks of a phishing scam, urgency combined with vague description with no verifiable details that aren't gleaned from my email address itself.
- orionblastar 6mo agoGone are the days when one can be anonymous on the Internet. Now, in some places, we have to prove our age and identity. This is leading to a digital ID. This will end badly.
- totetsu 6mo agolooks like the latest update was > Mounir IDRASSI - 7 hours ago > Thank you all for your feedback and your support in getting media attention through various social platforms. >After posting this, other developers in the security fields (like WireGuard) came forward to announce that they have the exact same issue. I understand why nobody talked publicly about this before and I'm glad that by going public I pushed others to do the same. >Positive aspect is that a Microsoft VP (Scott Hanselman) has announced on X that he will help address this issue affecting me and others. He also reached out to me and connected me with other Microsoft people to help address this issue. >I will let you know how things go.
- ece 6mo agoIf bitlocker wasn't crippled[1] on the home versions of Windows, this would be a non-issue. I hope a solution is found, even if it's 3rd party signing that works like the present solution. [1] https://www.microsoft.com/en-us/windows/compare-windows-11-home-vs-pro-versions#tabs1-2 https://www.microsoft.com/en-us/windows/compare-windows-11-h...